WEBVTT - Phishing, Spear Phishing and Whaling

0:00:04.120 --> 0:00:07.160
<v Speaker 1>Get in touch with technology with tech Stuff from how

0:00:07.200 --> 0:00:13.720
<v Speaker 1>stuff works dot com. Hey there, and welcome to tech Stuff.

0:00:13.760 --> 0:00:16.720
<v Speaker 1>I'm your host, Jonathan Strickland. I'm an executive producer with

0:00:16.720 --> 0:00:20.279
<v Speaker 1>how Stuff Works in a love all things tech, and

0:00:20.360 --> 0:00:23.560
<v Speaker 1>today we're going to kind of do a continuation on

0:00:23.680 --> 0:00:27.080
<v Speaker 1>our discussions about critical thinking and skepticism. I know I've

0:00:27.120 --> 0:00:29.760
<v Speaker 1>been talking about that a lot, but this is another

0:00:30.200 --> 0:00:33.600
<v Speaker 1>area where that's important, and recently in the news, there's

0:00:33.600 --> 0:00:36.559
<v Speaker 1>been a lot of talk about spear fishing. Now much

0:00:36.600 --> 0:00:41.440
<v Speaker 1>of that discussion centers on a report from that detailed

0:00:41.440 --> 0:00:45.839
<v Speaker 1>how Russian intelligence agents targeted the United States Democratic National

0:00:45.880 --> 0:00:49.600
<v Speaker 1>Committee or d NC with a spear phishing campaign that

0:00:49.760 --> 0:00:52.800
<v Speaker 1>ultimately allowed the malicious actors to make off with a

0:00:52.800 --> 0:00:57.360
<v Speaker 1>lot of sensitive and confidential information and infiltrate sensitive systems. Now,

0:00:57.400 --> 0:01:00.120
<v Speaker 1>I'm not going to get political on this EPISOD, so

0:01:00.280 --> 0:01:02.760
<v Speaker 1>that's not what I want to focus on. I rather

0:01:02.840 --> 0:01:05.840
<v Speaker 1>want to focus on the strategies that malicious actors use

0:01:06.240 --> 0:01:09.160
<v Speaker 1>to either steal information or convince people to hand it

0:01:09.200 --> 0:01:12.720
<v Speaker 1>over willingly through deception. So I'm going to talk about

0:01:12.800 --> 0:01:18.120
<v Speaker 1>concepts like social engineering, fishing, spear fishing, and whaling and

0:01:18.120 --> 0:01:21.360
<v Speaker 1>I'm listing them in that order because it involves moving

0:01:21.440 --> 0:01:25.520
<v Speaker 1>from a more general concept to a more specific application

0:01:25.760 --> 0:01:31.080
<v Speaker 1>of those concepts. So let's get it started with social engineering. Now,

0:01:31.120 --> 0:01:36.119
<v Speaker 1>generally speaking, social engineering, at least in this context, refers

0:01:36.160 --> 0:01:40.479
<v Speaker 1>to using deception and manipulation in order to get hold

0:01:40.520 --> 0:01:43.480
<v Speaker 1>of information. It's just, really it's just about tricking people

0:01:43.520 --> 0:01:47.119
<v Speaker 1>to give up stuff that normally they wouldn't part with,

0:01:47.560 --> 0:01:50.880
<v Speaker 1>and that's really all it boils down to. Typically, this

0:01:50.960 --> 0:01:54.440
<v Speaker 1>means that someone is pretending to be a trusted entity

0:01:54.640 --> 0:01:57.920
<v Speaker 1>and they work to convince a target or mark in

0:01:57.960 --> 0:02:01.400
<v Speaker 1>the old carnival speak, the marking the person that you

0:02:01.480 --> 0:02:05.600
<v Speaker 1>have marked as being vulnerable. You are trying to get

0:02:05.600 --> 0:02:08.400
<v Speaker 1>them to hand over information or even give them control

0:02:09.160 --> 0:02:12.720
<v Speaker 1>of their devices. So you might convince someone to install

0:02:12.880 --> 0:02:17.240
<v Speaker 1>some malware. It's disguised as something else, like an innocent file,

0:02:17.800 --> 0:02:20.440
<v Speaker 1>but your your job is to get them to do

0:02:20.560 --> 0:02:24.960
<v Speaker 1>something that compromises information or system information systems. And this

0:02:25.000 --> 0:02:27.720
<v Speaker 1>shows us yet again that critical thinking is a really

0:02:27.760 --> 0:02:30.919
<v Speaker 1>important skill. It's good to apply critical thinking when someone

0:02:31.000 --> 0:02:33.600
<v Speaker 1>is asking you for information or telling you that you

0:02:33.600 --> 0:02:38.040
<v Speaker 1>should install a program. Sometimes those are bad people, and

0:02:38.120 --> 0:02:40.520
<v Speaker 1>sometimes they're up to no good. Now, you can think

0:02:40.520 --> 0:02:43.880
<v Speaker 1>of a social engineer as a con artist, so it's

0:02:43.919 --> 0:02:48.040
<v Speaker 1>someone who uses psychological manipulation to get a specific reaction

0:02:48.200 --> 0:02:52.160
<v Speaker 1>from mark. Stage magicians and mentalists use those sort of

0:02:52.160 --> 0:02:55.640
<v Speaker 1>strategies or to entertain. They're not doing it to do

0:02:55.840 --> 0:03:00.480
<v Speaker 1>something underhanded. They're doing it in order to make people uh,

0:03:00.520 --> 0:03:04.400
<v Speaker 1>amazed or laugh or applaud. A stage magician, for example,

0:03:04.520 --> 0:03:07.480
<v Speaker 1>has to learn the art of misdirection. This is the

0:03:07.520 --> 0:03:10.239
<v Speaker 1>technique of getting an audience to pay attention to something

0:03:10.320 --> 0:03:14.280
<v Speaker 1>that is ultimately unimportant, at least as far as the

0:03:14.320 --> 0:03:17.200
<v Speaker 1>mechanics of a trick, and that's so that they don't

0:03:17.280 --> 0:03:20.320
<v Speaker 1>notice the actual important stuff that's going on. It gives

0:03:20.360 --> 0:03:23.200
<v Speaker 1>the magician the time and opportunity to pull off a trick.

0:03:23.760 --> 0:03:27.120
<v Speaker 1>A good magician can hold an audience's attention with some

0:03:27.200 --> 0:03:31.280
<v Speaker 1>mesmerizing stage work. They might incorporate clever pattern, but the

0:03:31.320 --> 0:03:33.600
<v Speaker 1>whole point is to keep focus off of something that

0:03:33.720 --> 0:03:37.920
<v Speaker 1>might otherwise spoil the illusion. Dr Robert Saldini, is a

0:03:38.000 --> 0:03:42.160
<v Speaker 1>professor emeritus of psychology and Marketing at Arizona State University,

0:03:42.360 --> 0:03:47.640
<v Speaker 1>outlined six basic principles of influence. These relate to strategies

0:03:47.680 --> 0:03:51.840
<v Speaker 1>that they're they're drivers that someone can employ to convince

0:03:51.880 --> 0:03:55.400
<v Speaker 1>another person to agree with what they are saying. And essentially,

0:03:55.680 --> 0:03:59.080
<v Speaker 1>these six broad principles can get someone to say yes.

0:03:59.240 --> 0:04:02.240
<v Speaker 1>It's the idea of influencing someone to agree to do something.

0:04:02.640 --> 0:04:05.920
<v Speaker 1>Understanding these principles can help you recognize when someone is

0:04:05.960 --> 0:04:09.400
<v Speaker 1>trying to use those strategies on you. But these are

0:04:09.440 --> 0:04:14.080
<v Speaker 1>strategies that rely on very human traits. They work because

0:04:14.120 --> 0:04:17.640
<v Speaker 1>of the way we're wired. More or less, it's even

0:04:17.640 --> 0:04:19.640
<v Speaker 1>being aware of them doesn't mean that you will be

0:04:19.720 --> 0:04:24.159
<v Speaker 1>immune to them, because it's it's very much dependent upon

0:04:24.200 --> 0:04:27.520
<v Speaker 1>what it means to be human. So Childni cites other

0:04:27.560 --> 0:04:32.440
<v Speaker 1>psychologists who identified what they called judgmental heuristics. You can

0:04:32.480 --> 0:04:36.200
<v Speaker 1>think of these as sort of cognitive shortcuts. They are

0:04:36.279 --> 0:04:39.200
<v Speaker 1>basic rules that we accept as being generally true, so

0:04:39.240 --> 0:04:42.279
<v Speaker 1>it's sort of like a foundational statement that we would

0:04:42.279 --> 0:04:45.800
<v Speaker 1>not question. But if someone knows how those work, they

0:04:45.800 --> 0:04:48.440
<v Speaker 1>can take advantage of it. So, in other words, if

0:04:48.440 --> 0:04:51.120
<v Speaker 1>someone is really good at using these principles, you might

0:04:51.160 --> 0:04:53.640
<v Speaker 1>not be aware of it right away. And I certainly

0:04:53.640 --> 0:04:56.080
<v Speaker 1>consider myself to be vulnerable to them. I know I'm

0:04:56.160 --> 0:04:58.479
<v Speaker 1>vulnerable to them. I can think of examples where people

0:04:58.600 --> 0:05:01.679
<v Speaker 1>use these technique U on me and it worked. Sales

0:05:01.720 --> 0:05:05.200
<v Speaker 1>people in particular tend to really focus on these their

0:05:05.360 --> 0:05:08.479
<v Speaker 1>entire books out there that are all about how to

0:05:08.640 --> 0:05:13.600
<v Speaker 1>leverage these principles in order to make sales, make business deals,

0:05:14.360 --> 0:05:18.000
<v Speaker 1>et cetera. So what are the six big categories. Well,

0:05:18.279 --> 0:05:21.880
<v Speaker 1>the first is the rule of reciprocation. That's our tendency

0:05:21.960 --> 0:05:25.200
<v Speaker 1>to want to repay someone who has done something on

0:05:25.200 --> 0:05:29.640
<v Speaker 1>our behalf. Essentially, this comes down to the concept of favors.

0:05:29.720 --> 0:05:32.839
<v Speaker 1>So an example you might have encountered could be free samples.

0:05:33.240 --> 0:05:36.320
<v Speaker 1>Merchants know that a free sample can create the urge

0:05:36.320 --> 0:05:39.359
<v Speaker 1>within a potential customer to buy a product because that

0:05:39.400 --> 0:05:43.240
<v Speaker 1>person feels obligated after having accepted a sample. So if

0:05:43.279 --> 0:05:46.080
<v Speaker 1>I'm sitting at a table and I have samples of

0:05:46.160 --> 0:05:49.160
<v Speaker 1>let's say it's olive oil, I've got different little bowls

0:05:49.160 --> 0:05:51.159
<v Speaker 1>of olive oil, and you can dip a little bit

0:05:51.240 --> 0:05:53.200
<v Speaker 1>of bread in there and taste them, and I'm there

0:05:53.240 --> 0:05:56.160
<v Speaker 1>saying I'm here to answer any questions. Do you like it?

0:05:56.240 --> 0:05:59.520
<v Speaker 1>What do you think? We have the social pressure within

0:05:59.640 --> 0:06:02.080
<v Speaker 1>us to say, oh, I like it a lot, even

0:06:02.120 --> 0:06:04.720
<v Speaker 1>if we don't. We have that social pressure, Like very

0:06:04.760 --> 0:06:06.359
<v Speaker 1>few of us would say, oh, I don't like this

0:06:06.440 --> 0:06:09.680
<v Speaker 1>at all to someone who seems like they are invested

0:06:09.720 --> 0:06:13.400
<v Speaker 1>in your answer. So we feel obligated to go along

0:06:13.440 --> 0:06:15.520
<v Speaker 1>with it. And we may feel obligated because we have

0:06:15.600 --> 0:06:19.080
<v Speaker 1>accepted something that in return we will buy something even

0:06:19.160 --> 0:06:22.720
<v Speaker 1>if we didn't like the thing, because we feel this

0:06:22.960 --> 0:06:27.640
<v Speaker 1>social pressure. And this goes along with what it means

0:06:27.680 --> 0:06:29.640
<v Speaker 1>to be human. I'll touch back on that when we

0:06:29.680 --> 0:06:32.159
<v Speaker 1>get towards the end of these principles. So most people

0:06:32.200 --> 0:06:34.880
<v Speaker 1>don't like to feel that they are under some sense

0:06:34.880 --> 0:06:37.679
<v Speaker 1>of obligation to someone else. They don't like to feel

0:06:37.680 --> 0:06:42.000
<v Speaker 1>they owe somebody something, and so they will very quickly

0:06:42.160 --> 0:06:45.200
<v Speaker 1>try to act to even the scales right so that

0:06:45.240 --> 0:06:49.159
<v Speaker 1>they are no longer obligated. So rule of reciprocation is

0:06:49.200 --> 0:06:53.359
<v Speaker 1>the first principle. Next is scarcity. People tend to want

0:06:53.440 --> 0:06:56.920
<v Speaker 1>more of stuff that they can have less of. That's

0:06:56.920 --> 0:07:00.200
<v Speaker 1>the basic idea. And you can look at this with

0:07:00.360 --> 0:07:03.880
<v Speaker 1>just like the prices for precious metals. Precious metals are

0:07:03.880 --> 0:07:07.159
<v Speaker 1>precious largely because of their scarcity, because they're so hard

0:07:07.200 --> 0:07:09.080
<v Speaker 1>to get and there's not a whole lot of it.

0:07:09.440 --> 0:07:11.640
<v Speaker 1>That's what drives up their value. People want it more

0:07:11.720 --> 0:07:15.440
<v Speaker 1>because it's harder to get. The entire diamond industry is

0:07:15.480 --> 0:07:19.240
<v Speaker 1>based off of this concept. There are plenty of diamonds,

0:07:19.320 --> 0:07:23.560
<v Speaker 1>There are tons of diamonds. They are not even rare.

0:07:23.680 --> 0:07:29.040
<v Speaker 1>But because the world's supply of natural diamonds is controlled

0:07:29.200 --> 0:07:33.360
<v Speaker 1>essentially by a single company, that company can control the

0:07:33.440 --> 0:07:37.280
<v Speaker 1>scarcity of diamonds and thus inflate their value. Because people

0:07:37.320 --> 0:07:40.559
<v Speaker 1>want what they can't have, So offering someone a chance

0:07:40.600 --> 0:07:44.320
<v Speaker 1>to experience something or possess something that has extremely limited

0:07:44.320 --> 0:07:49.120
<v Speaker 1>availability is a really useful tactic. If you tell someone, hey,

0:07:49.120 --> 0:07:51.480
<v Speaker 1>this service that we have, we're gonna get rid of

0:07:51.520 --> 0:07:54.320
<v Speaker 1>it in a week, typically you see a lot more

0:07:54.360 --> 0:07:56.560
<v Speaker 1>people try and take advantage of that service before it

0:07:56.600 --> 0:08:00.000
<v Speaker 1>goes away forever. It's an incredibly useful way of getting

0:08:00.080 --> 0:08:02.600
<v Speaker 1>people to do something you want them to do. Next

0:08:02.720 --> 0:08:05.640
<v Speaker 1>is the principle of authority, which is the notion that

0:08:05.680 --> 0:08:07.920
<v Speaker 1>people will tend to go along with someone they view

0:08:08.040 --> 0:08:11.280
<v Speaker 1>as being an expert or being credible. So have you

0:08:11.280 --> 0:08:14.600
<v Speaker 1>ever encountered a problem and thought, Uh, someone smarter than

0:08:14.600 --> 0:08:16.800
<v Speaker 1>I am is going to handle this, or you just

0:08:16.880 --> 0:08:20.680
<v Speaker 1>assume that someone more capable than you has the situation covered.

0:08:21.080 --> 0:08:24.280
<v Speaker 1>Maybe you were present when an emergency happened and you

0:08:24.320 --> 0:08:26.640
<v Speaker 1>look around to see if someone else jumps to help,

0:08:26.720 --> 0:08:29.360
<v Speaker 1>because you think, well, clearly, there's gotta be someone here

0:08:29.400 --> 0:08:32.080
<v Speaker 1>who's better at handling this kind of situation than I am,

0:08:32.320 --> 0:08:34.920
<v Speaker 1>so I'm gonna step back and allow that to happen. Well,

0:08:34.920 --> 0:08:37.760
<v Speaker 1>that behavior shows that we frequently will defer and even

0:08:37.840 --> 0:08:41.040
<v Speaker 1>seek out people who appear to be more knowledgeable or

0:08:41.200 --> 0:08:45.400
<v Speaker 1>capable than ourselves under certain situations. So if someone poses

0:08:45.480 --> 0:08:48.760
<v Speaker 1>as a person of authority convincingly, they can more easily

0:08:48.800 --> 0:08:52.480
<v Speaker 1>persuade people to do stuff. The fourth principle of influence,

0:08:52.480 --> 0:08:56.320
<v Speaker 1>according to Cialdini, is consistency. This is related to the

0:08:56.360 --> 0:08:59.880
<v Speaker 1>concept of commitment committing to do something. If you get

0:09:00.000 --> 0:09:03.839
<v Speaker 1>someone to agree to a small initial commitment, that can

0:09:03.880 --> 0:09:07.040
<v Speaker 1>set the ground for a larger commitment further down the road.

0:09:07.120 --> 0:09:10.280
<v Speaker 1>So a classic example in a scam could be the

0:09:10.360 --> 0:09:13.600
<v Speaker 1>Nigerian scam. A lot of Nigerian scams will start off

0:09:13.640 --> 0:09:16.240
<v Speaker 1>where the scam artist first asks for a relatively small

0:09:16.280 --> 0:09:19.079
<v Speaker 1>amount of money because they say, hey, there's a huge

0:09:19.120 --> 0:09:22.160
<v Speaker 1>amount of money in this country. Has your name on it.

0:09:22.160 --> 0:09:24.480
<v Speaker 1>It's it's clearly not meant for you, but because it

0:09:24.480 --> 0:09:26.280
<v Speaker 1>has your name on it, we can get it to you.

0:09:26.720 --> 0:09:29.400
<v Speaker 1>It's an enormous sum. However, in order for me to

0:09:29.440 --> 0:09:31.400
<v Speaker 1>get this money to you, first, I'm gonna need a

0:09:31.440 --> 0:09:33.920
<v Speaker 1>small amount of money from you to help secure this,

0:09:34.200 --> 0:09:36.640
<v Speaker 1>and then we can get you rich. And people will

0:09:36.640 --> 0:09:38.959
<v Speaker 1>say okay, And then the scam ars might come back

0:09:39.000 --> 0:09:40.640
<v Speaker 1>and say, oh, as it turns out, I'm gonna need

0:09:40.679 --> 0:09:42.319
<v Speaker 1>a little bit more money because I'm gonna have to

0:09:42.400 --> 0:09:46.080
<v Speaker 1>bribe some officials here in order to get your wealth

0:09:46.240 --> 0:09:49.120
<v Speaker 1>to you, and so on and so on. The idea

0:09:49.160 --> 0:09:52.319
<v Speaker 1>being that because you've already made an initial commitment, you

0:09:52.360 --> 0:09:55.800
<v Speaker 1>would be willing to make a larger subsequent commitment. And

0:09:55.880 --> 0:09:58.559
<v Speaker 1>this can happen not just in scams, it can happen

0:09:58.559 --> 0:10:04.640
<v Speaker 1>in completelygitimate, although sometimes questionably ethical applications. That in the

0:10:04.679 --> 0:10:07.679
<v Speaker 1>Principles is the principle of liking, which means we're more

0:10:07.720 --> 0:10:12.440
<v Speaker 1>easily influenced by people we like. This is not brain surgery, right,

0:10:12.920 --> 0:10:15.840
<v Speaker 1>If you like someone, you're more willing to agree with

0:10:15.920 --> 0:10:19.199
<v Speaker 1>them and to do things that they need you to do. Now,

0:10:19.480 --> 0:10:22.040
<v Speaker 1>Sheldeoni states there are three factors that go into whether

0:10:22.120 --> 0:10:25.280
<v Speaker 1>or not we actually like someone. First, we tend to

0:10:25.360 --> 0:10:28.680
<v Speaker 1>like people who are similar to ourselves. The more alike

0:10:28.760 --> 0:10:30.800
<v Speaker 1>they are to ourselves, at least to a certain extent,

0:10:31.120 --> 0:10:33.800
<v Speaker 1>the more we tend to like them. Second, we like

0:10:33.920 --> 0:10:38.240
<v Speaker 1>people who complement us because we're vain. We're egotistical creatures.

0:10:38.640 --> 0:10:40.040
<v Speaker 1>If you come up to me and say, hey, I

0:10:40.080 --> 0:10:42.600
<v Speaker 1>really like your work, I am far more likely to

0:10:42.679 --> 0:10:45.720
<v Speaker 1>like you. And Third, we like people who will work

0:10:45.800 --> 0:10:49.079
<v Speaker 1>with us towards a mutual goal. If we both need

0:10:49.120 --> 0:10:52.640
<v Speaker 1>to get a specific task done, and you help me

0:10:52.760 --> 0:10:55.640
<v Speaker 1>do that task, I am more likely to like you.

0:10:55.800 --> 0:10:58.400
<v Speaker 1>So a scam artist might try to wheel out some

0:10:58.720 --> 0:11:01.240
<v Speaker 1>information about you in order to make it seem as

0:11:01.280 --> 0:11:04.439
<v Speaker 1>if the artist also shares the similar interests and values

0:11:04.480 --> 0:11:07.960
<v Speaker 1>that you have, and try and create this pathway to

0:11:08.040 --> 0:11:10.640
<v Speaker 1>get you to like the scam artists so that in return,

0:11:11.360 --> 0:11:13.680
<v Speaker 1>you will actually do whatever the scam artist wants you

0:11:13.720 --> 0:11:18.240
<v Speaker 1>to do. The sixth principle is consensus, which essentially says

0:11:18.520 --> 0:11:20.360
<v Speaker 1>that when we're in doubt, we tend to look at

0:11:20.360 --> 0:11:22.480
<v Speaker 1>what other people are doing so that we can get

0:11:22.520 --> 0:11:25.280
<v Speaker 1>some direction over what we should do. Now, I certainly

0:11:25.360 --> 0:11:28.560
<v Speaker 1>identify with this. I think about just about any situation

0:11:28.600 --> 0:11:31.120
<v Speaker 1>I've been in in which I was joining a group

0:11:31.160 --> 0:11:34.000
<v Speaker 1>of people working together on an activity. Maybe we're all

0:11:34.520 --> 0:11:37.480
<v Speaker 1>doing the same thing over and over, like folding T shirts.

0:11:37.480 --> 0:11:40.480
<v Speaker 1>That's an easy one. We're all folding T shirts, and

0:11:40.640 --> 0:11:42.680
<v Speaker 1>I keep looking over to the left and right to

0:11:42.679 --> 0:11:44.280
<v Speaker 1>see how other people are doing it, so that I

0:11:44.280 --> 0:11:46.199
<v Speaker 1>feel like I'm doing it the right way, that I'm

0:11:46.240 --> 0:11:49.520
<v Speaker 1>not messing up. I have this incredible social pressure on

0:11:49.559 --> 0:11:53.440
<v Speaker 1>me to do it correctly, and rather than try and

0:11:53.800 --> 0:11:56.960
<v Speaker 1>learn this in a more formal way, you know, a

0:11:57.000 --> 0:12:00.719
<v Speaker 1>more process oriented way, I'm doing it looking at how

0:12:00.720 --> 0:12:03.640
<v Speaker 1>everyone else is doing this. Now, if everyone else is

0:12:03.679 --> 0:12:06.320
<v Speaker 1>doing this quote unquote the correct way, that's fine. But

0:12:06.360 --> 0:12:09.440
<v Speaker 1>if people are doing things incorrectly, then all I'm doing

0:12:09.520 --> 0:12:11.360
<v Speaker 1>is adding to the number of people who are doing

0:12:11.400 --> 0:12:14.439
<v Speaker 1>something incorrectly. But there's again, is a lot of social

0:12:14.480 --> 0:12:17.599
<v Speaker 1>pressure at play here for you to do as the

0:12:17.640 --> 0:12:21.920
<v Speaker 1>group does. And this is not just psychobabble. These principles

0:12:22.160 --> 0:12:26.640
<v Speaker 1>put into words behaviors that humans have developed as social creatures.

0:12:27.320 --> 0:12:30.720
<v Speaker 1>Human survival has largely depended upon our working together, and

0:12:30.760 --> 0:12:35.040
<v Speaker 1>so we've developed these behaviors that promote cooperation and they

0:12:35.080 --> 0:12:41.239
<v Speaker 1>discourage inhibiting cooperation. Understanding those behaviors and then subtly leveraging

0:12:41.320 --> 0:12:44.640
<v Speaker 1>them can have a really big impact on interactions, and

0:12:44.640 --> 0:12:48.000
<v Speaker 1>that plays right into the hands of social engineers. So

0:12:48.240 --> 0:12:51.960
<v Speaker 1>if you happen to know people tend to follow these

0:12:52.000 --> 0:12:57.199
<v Speaker 1>principles because humans as a species have sort of evolved

0:12:57.280 --> 0:13:00.000
<v Speaker 1>to be these social creatures, then you can take advantag

0:13:00.040 --> 0:13:02.239
<v Speaker 1>edge of that. Now, granted they are going to be outliers.

0:13:02.240 --> 0:13:05.360
<v Speaker 1>There will be people who do not conform, they do

0:13:05.400 --> 0:13:08.679
<v Speaker 1>not adhere to these principles, they don't have any connection

0:13:08.760 --> 0:13:11.640
<v Speaker 1>to them, But more frequently than not, you're going to

0:13:11.679 --> 0:13:15.120
<v Speaker 1>find that they work and that they work on you. Next,

0:13:15.200 --> 0:13:18.400
<v Speaker 1>I'm going to define the terms like fishing, spear fishing,

0:13:18.440 --> 0:13:21.440
<v Speaker 1>and whaling, and we'll explore some specific tactics and stories

0:13:21.480 --> 0:13:24.720
<v Speaker 1>related to those practices. But first let's take a quick

0:13:24.760 --> 0:13:35.760
<v Speaker 1>break to thank our sponsor. All right, So social engineering

0:13:35.800 --> 0:13:37.800
<v Speaker 1>is all about manipulating people to give them to do

0:13:37.840 --> 0:13:40.599
<v Speaker 1>what you want, typically in a way that involves deception

0:13:40.679 --> 0:13:44.880
<v Speaker 1>and handing over confidential information. But what is fishing all about?

0:13:45.120 --> 0:13:48.040
<v Speaker 1>And it's spelled p h I s H I n

0:13:48.080 --> 0:13:51.800
<v Speaker 1>G by the way, fishing with a pH Fishing describes

0:13:51.840 --> 0:13:54.960
<v Speaker 1>the practice of tricking people into handing over sensitive information

0:13:55.280 --> 0:13:59.440
<v Speaker 1>through some digital means. Most frequently we talk about using

0:13:59.720 --> 0:14:02.640
<v Speaker 1>e ail as a way of phishing for data, but

0:14:03.000 --> 0:14:07.959
<v Speaker 1>you could use a spoofed website, you could use instant messaging,

0:14:08.360 --> 0:14:12.280
<v Speaker 1>but it doesn't really matter. The basic concept is the same.

0:14:12.320 --> 0:14:15.679
<v Speaker 1>You're fishing for data. I find it interesting, by the way,

0:14:15.720 --> 0:14:18.000
<v Speaker 1>that we have a lot of nautically themed terms to

0:14:18.080 --> 0:14:22.160
<v Speaker 1>describe different behaviors on the Internet, because there's fishing, their

0:14:22.200 --> 0:14:26.080
<v Speaker 1>spear fishing, there's whaling, but there's also trolling. Trolling refers

0:14:26.160 --> 0:14:29.080
<v Speaker 1>not to mythical monsters from fairy tales, but from the

0:14:29.080 --> 0:14:32.600
<v Speaker 1>practice of dragging a net behind a boat to troll

0:14:32.840 --> 0:14:35.640
<v Speaker 1>in an effort to scoop up a catch. Trolling on

0:14:35.680 --> 0:14:38.360
<v Speaker 1>the Internet originally referred to people who would go into

0:14:38.800 --> 0:14:41.760
<v Speaker 1>message forums and they would lay down a trap, which

0:14:41.760 --> 0:14:44.640
<v Speaker 1>would be they would post something intended to get a

0:14:44.760 --> 0:14:48.440
<v Speaker 1>rise out of members of the forum, legitimate members, so

0:14:48.800 --> 0:14:51.600
<v Speaker 1>they weren't necessarily aiming at anyone in particular. They were

0:14:51.640 --> 0:14:54.000
<v Speaker 1>just kind of laying a trap for anybody who was

0:14:54.200 --> 0:14:57.320
<v Speaker 1>gullible enough to fall into it. The goal was just

0:14:57.400 --> 0:15:00.280
<v Speaker 1>to rile people up, and why would you do that. Well,

0:15:00.360 --> 0:15:02.560
<v Speaker 1>some people just want to watch the world burn. I

0:15:02.600 --> 0:15:04.960
<v Speaker 1>guess they like to think that they were able to

0:15:05.000 --> 0:15:08.680
<v Speaker 1>have influence on another person and that brings them some

0:15:09.160 --> 0:15:12.240
<v Speaker 1>mean sense of joy. It's not great, but it does

0:15:12.320 --> 0:15:16.800
<v Speaker 1>happen far too frequently. Or sometimes the troll actually has

0:15:16.840 --> 0:15:20.440
<v Speaker 1>ulterior motives beyond just upsetting people. Maybe you have someone

0:15:20.480 --> 0:15:23.120
<v Speaker 1>who's running a different message board, and so what they're

0:15:23.120 --> 0:15:26.440
<v Speaker 1>doing is they're essentially sabotaging what they see as competition.

0:15:26.680 --> 0:15:29.840
<v Speaker 1>But whatever the motivation, the practice involved being obnoxious in

0:15:29.920 --> 0:15:32.640
<v Speaker 1>one way or another in an attempt to get at

0:15:32.680 --> 0:15:35.280
<v Speaker 1>least a hit or two from well meaning but misguided

0:15:35.280 --> 0:15:38.880
<v Speaker 1>forum members. And I say misguided because the person's anger

0:15:39.000 --> 0:15:42.040
<v Speaker 1>or frustration was the trolls goal all along. They're not

0:15:42.520 --> 0:15:46.120
<v Speaker 1>necessarily arguing something they actually believe in. All we wanted

0:15:46.160 --> 0:15:48.880
<v Speaker 1>to do was get someone upset. So if you get upset,

0:15:49.040 --> 0:15:51.600
<v Speaker 1>the troll wins. So the only real way to win

0:15:51.800 --> 0:15:54.440
<v Speaker 1>is not to play. And that's why you often hear

0:15:54.480 --> 0:15:57.040
<v Speaker 1>people say don't feed the trolls. Problem is, if you

0:15:57.040 --> 0:15:59.600
<v Speaker 1>don't feed the trolls, sometimes trolls will just keep on

0:15:59.680 --> 0:16:05.520
<v Speaker 1>trying to get people to agree to awful, awful things,

0:16:05.720 --> 0:16:08.400
<v Speaker 1>So that philosophy only goes so far as well, and

0:16:08.440 --> 0:16:11.600
<v Speaker 1>it's only applicable in certain situations. But that's another podcast.

0:16:12.080 --> 0:16:14.680
<v Speaker 1>Fishing is similar in a lot of ways to trolling,

0:16:14.720 --> 0:16:17.600
<v Speaker 1>except instead of trying to irritate people, you're trying to

0:16:17.640 --> 0:16:20.960
<v Speaker 1>trick people into handing over information they should definitely not

0:16:21.240 --> 0:16:24.960
<v Speaker 1>hand over. Fishing is a general approach. The attacker does

0:16:25.000 --> 0:16:28.360
<v Speaker 1>not necessarily have a particular target in mind. It's kind

0:16:28.360 --> 0:16:31.680
<v Speaker 1>of a blanket attack. They don't really care who ends

0:16:31.760 --> 0:16:33.800
<v Speaker 1>up being a victim. All they want to do is

0:16:33.840 --> 0:16:37.200
<v Speaker 1>gather as many hits as possible. Just doesn't matter. From

0:16:37.240 --> 0:16:41.680
<v Speaker 1>where as such this, phishing messages tend to be pretty generic.

0:16:42.320 --> 0:16:45.320
<v Speaker 1>Phishing emails may appear to come from a legitimate source.

0:16:45.440 --> 0:16:47.520
<v Speaker 1>On a casual glance, they might look like they were

0:16:47.520 --> 0:16:50.440
<v Speaker 1>sent from an actual company, like a bank or a

0:16:50.480 --> 0:16:54.640
<v Speaker 1>government organization. There are countless variations, but they all try

0:16:54.720 --> 0:16:57.480
<v Speaker 1>to fool the recipient into taking an action that will

0:16:57.600 --> 0:17:01.200
<v Speaker 1>ultimately result in a bad outcome for the target. So,

0:17:01.280 --> 0:17:03.520
<v Speaker 1>for example, you might get an email from a bank

0:17:03.640 --> 0:17:05.800
<v Speaker 1>stating that you have an old account with money in

0:17:05.840 --> 0:17:08.080
<v Speaker 1>it and you should transfer that money out of your account.

0:17:08.480 --> 0:17:10.879
<v Speaker 1>It is essentially saying, hey, you got free money, and

0:17:10.920 --> 0:17:13.399
<v Speaker 1>this bank asks that you fill out some information so

0:17:13.440 --> 0:17:16.240
<v Speaker 1>that you can retrieve your cash. But in reality, the

0:17:16.280 --> 0:17:18.679
<v Speaker 1>emails coming from a phishing scheme and it's looking to

0:17:18.720 --> 0:17:22.120
<v Speaker 1>harvest as much confidential information from users as possible. Maybe

0:17:22.119 --> 0:17:25.639
<v Speaker 1>they're saying, give us your current bank account information so

0:17:25.680 --> 0:17:27.800
<v Speaker 1>that we can transfer the money. We can wire it

0:17:27.880 --> 0:17:31.679
<v Speaker 1>from this old account into your current account, but in

0:17:31.760 --> 0:17:34.680
<v Speaker 1>reality they just want access to your current account. That's

0:17:34.760 --> 0:17:38.199
<v Speaker 1>a pretty clumsy example, but it is an example of

0:17:38.200 --> 0:17:42.199
<v Speaker 1>something that could actually happen. Often, the email address in

0:17:42.240 --> 0:17:44.639
<v Speaker 1>a message can be a dead giveaway whether the message

0:17:44.640 --> 0:17:47.280
<v Speaker 1>is legitimate or not. You can look at the originating

0:17:47.320 --> 0:17:50.720
<v Speaker 1>email address and say, well, it says it's from Gmail,

0:17:50.960 --> 0:17:55.280
<v Speaker 1>but the domain on the email is not related at

0:17:55.320 --> 0:17:58.320
<v Speaker 1>all to Google. Well that's a dead giveaway. Chances are

0:17:58.359 --> 0:18:02.679
<v Speaker 1>you're looking at a scam if email address does not

0:18:02.800 --> 0:18:06.879
<v Speaker 1>match whatever entity it claims to be from. And I

0:18:06.920 --> 0:18:10.200
<v Speaker 1>doubt any legitimate organization would ever ask for sensitive details

0:18:10.240 --> 0:18:13.040
<v Speaker 1>to be sent over email. Almost every single one if

0:18:13.080 --> 0:18:15.560
<v Speaker 1>they respond to these kind of attacks, says we will

0:18:15.640 --> 0:18:19.800
<v Speaker 1>never ask for your personal information over email, particularly since

0:18:19.840 --> 0:18:23.479
<v Speaker 1>there's no guarantee that the recipient is using encryption on

0:18:23.560 --> 0:18:27.520
<v Speaker 1>their emails, So if you're not using an encrypted email service,

0:18:27.880 --> 0:18:31.240
<v Speaker 1>there's no guarantee that a third party listening in wouldn't

0:18:31.320 --> 0:18:34.080
<v Speaker 1>get access to that information anyway, even if everything else

0:18:34.119 --> 0:18:37.960
<v Speaker 1>was legitimate. So that being said, it is possible to

0:18:38.000 --> 0:18:41.439
<v Speaker 1>forge an email address so that a message appears to

0:18:41.480 --> 0:18:45.080
<v Speaker 1>be from an official, legitimate source. There's nothing in the

0:18:45.160 --> 0:18:48.200
<v Speaker 1>email protocol on its own, just the regular email protocol

0:18:48.520 --> 0:18:52.280
<v Speaker 1>that verifies an address in the front field is actually

0:18:52.320 --> 0:18:55.400
<v Speaker 1>a legitimate address. Now you can do some snooping yourself.

0:18:55.680 --> 0:18:59.280
<v Speaker 1>You can examine email headers, which might require activating a

0:18:59.320 --> 0:19:03.080
<v Speaker 1>specific feature in your email interface like in Gmail. I

0:19:03.119 --> 0:19:07.480
<v Speaker 1>think it's reveal source or something along those lines. Uh oh,

0:19:07.520 --> 0:19:09.320
<v Speaker 1>show original is what it is. That's what it is.

0:19:09.560 --> 0:19:12.240
<v Speaker 1>You choose show original, and that's gonna give you kind

0:19:12.280 --> 0:19:16.160
<v Speaker 1>of the hypertext version of the email, and that will

0:19:16.200 --> 0:19:19.040
<v Speaker 1>include listing all the servers that the email has passed

0:19:19.280 --> 0:19:23.879
<v Speaker 1>through with the line received colon from, and at the

0:19:23.880 --> 0:19:28.720
<v Speaker 1>bottom of that section, the last received from would represent

0:19:28.840 --> 0:19:32.760
<v Speaker 1>the original computer that sent the email. And if you

0:19:32.800 --> 0:19:36.360
<v Speaker 1>look at that and the original computers domain is different

0:19:36.480 --> 0:19:40.600
<v Speaker 1>from the official domain. Again, that could be a red flag.

0:19:40.640 --> 0:19:44.639
<v Speaker 1>It's not necessarily proof positive, but it does indicate that

0:19:44.680 --> 0:19:46.679
<v Speaker 1>it could be a malicious email and you should be

0:19:46.720 --> 0:19:49.800
<v Speaker 1>careful about it. On the admin side of this, if

0:19:49.800 --> 0:19:53.560
<v Speaker 1>you were a system administrator, organizations can implement what is

0:19:53.560 --> 0:19:58.120
<v Speaker 1>called a sender policy framework to prevent forged email addresses,

0:19:58.600 --> 0:20:02.800
<v Speaker 1>which is an email validation protocol, and essentially it allows

0:20:02.840 --> 0:20:06.760
<v Speaker 1>an organization to map specific I P addresses that are

0:20:06.800 --> 0:20:10.920
<v Speaker 1>authorized to be associated with email addresses containing the organization's

0:20:10.960 --> 0:20:13.879
<v Speaker 1>web domain. So, in other words, it says, if someone

0:20:13.920 --> 0:20:16.480
<v Speaker 1>tries to send an email and they claim that email

0:20:16.520 --> 0:20:20.560
<v Speaker 1>is from US, check to make sure their IP address

0:20:20.760 --> 0:20:24.720
<v Speaker 1>is on this list of authorized IP addresses, and if

0:20:24.720 --> 0:20:29.080
<v Speaker 1>it isn't, don't allow our email. Don't allow that that

0:20:29.200 --> 0:20:33.280
<v Speaker 1>from field to display our domain. It's essentially saying check

0:20:33.320 --> 0:20:36.359
<v Speaker 1>here to make sure that it's legit. But again, you

0:20:36.400 --> 0:20:39.080
<v Speaker 1>have to implement this. It's not something that is natively

0:20:39.280 --> 0:20:43.520
<v Speaker 1>part of the email protocol. Now. I've received countless phishing

0:20:43.600 --> 0:20:45.680
<v Speaker 1>emails over the years, and my favorites are the ones

0:20:45.720 --> 0:20:48.640
<v Speaker 1>from companies or banks that I have never done any

0:20:48.680 --> 0:20:52.320
<v Speaker 1>business with. But even those types of obvious scams can

0:20:52.359 --> 0:20:55.200
<v Speaker 1>fool people. They might think, Hey, I might be able

0:20:55.200 --> 0:20:57.240
<v Speaker 1>to get some free money because these folks think I

0:20:57.280 --> 0:20:59.920
<v Speaker 1>have cash in their coffers, so I'll just play along,

0:21:00.440 --> 0:21:02.840
<v Speaker 1>and I can essentially get some poor SAPs doughe just

0:21:02.880 --> 0:21:04.800
<v Speaker 1>because they happen to have the same name as I

0:21:04.840 --> 0:21:07.920
<v Speaker 1>do that stinks to be them. Only it turns out

0:21:07.960 --> 0:21:10.600
<v Speaker 1>that the SAP all along was the person who received

0:21:10.600 --> 0:21:13.560
<v Speaker 1>the email, because they will end up handing over sensitive

0:21:13.600 --> 0:21:16.400
<v Speaker 1>information to an attacker rather than getting hold of someone

0:21:16.440 --> 0:21:19.840
<v Speaker 1>else's money. A phishing attack doesn't need to get that

0:21:19.880 --> 0:21:22.800
<v Speaker 1>many hits to be a success. Is a pretty cheap

0:21:23.280 --> 0:21:26.879
<v Speaker 1>way of attacking people. It's not expensive to mock up

0:21:26.920 --> 0:21:29.479
<v Speaker 1>an email that looks like it came from an official source,

0:21:29.800 --> 0:21:33.000
<v Speaker 1>and it's also not that expensive to email hundreds of

0:21:33.040 --> 0:21:35.679
<v Speaker 1>thousands of people. It's pretty easy to do so if

0:21:35.720 --> 0:21:38.640
<v Speaker 1>you cast a wide enough net, you're sure to get

0:21:38.680 --> 0:21:40.760
<v Speaker 1>some hits. There might not be a lot, but you

0:21:40.800 --> 0:21:43.160
<v Speaker 1>don't really need a lot to actually make it profitable.

0:21:43.600 --> 0:21:46.159
<v Speaker 1>So it's not an efficient way to trick people, but

0:21:46.240 --> 0:21:49.720
<v Speaker 1>it can still make you money, though not at a

0:21:49.720 --> 0:21:52.600
<v Speaker 1>super high profitability. But also you would be a total

0:21:52.680 --> 0:21:55.159
<v Speaker 1>scumbag for doing it if you try chose to do

0:21:55.200 --> 0:21:58.800
<v Speaker 1>this kind of stuff. So that's fishing. What is spear

0:21:58.880 --> 0:22:01.439
<v Speaker 1>fishing because that's been the news quite a bit with

0:22:01.480 --> 0:22:03.800
<v Speaker 1>this d n C stuff. Well, as I mentioned earlier,

0:22:03.840 --> 0:22:06.439
<v Speaker 1>we're moving from the general to the more specific. So

0:22:06.480 --> 0:22:09.639
<v Speaker 1>spear phishing is phishing. It uses the same sort of

0:22:09.680 --> 0:22:12.800
<v Speaker 1>general approaches phishing, except this time the target is a

0:22:12.880 --> 0:22:17.040
<v Speaker 1>defined one. Instead of it just being a widespread blanket

0:22:17.040 --> 0:22:21.680
<v Speaker 1>attack against anyone and everyone, this is a targeted attack.

0:22:22.080 --> 0:22:26.119
<v Speaker 1>It's targeting a specific company or organization. The emails or

0:22:26.119 --> 0:22:29.399
<v Speaker 1>other messages take aim at the people who work in

0:22:29.520 --> 0:22:33.080
<v Speaker 1>those organizations or for those companies. The attacker might tailor

0:22:33.160 --> 0:22:36.359
<v Speaker 1>their approach specifically for the target. They might be able

0:22:36.400 --> 0:22:40.280
<v Speaker 1>to use the target's actual name in the email. UM

0:22:40.359 --> 0:22:43.360
<v Speaker 1>that's a pretty smart move. Actually, it's likely to increase

0:22:43.400 --> 0:22:47.080
<v Speaker 1>the number of successful hits. So rather than sending out

0:22:47.119 --> 0:22:50.000
<v Speaker 1>generic hey you've got some cash and X bank that

0:22:50.080 --> 0:22:52.880
<v Speaker 1>you need to retrieve, or dear Amazon customer, we see

0:22:52.880 --> 0:22:54.960
<v Speaker 1>you overpaid on your last order, so fill out this

0:22:55.000 --> 0:22:58.520
<v Speaker 1>information for a refund, a spear fisher might take aim

0:22:58.560 --> 0:23:02.760
<v Speaker 1>using details that apply to a specific targeted organization. The

0:23:02.800 --> 0:23:06.520
<v Speaker 1>actual emails might not look that different from general phishing ones,

0:23:06.640 --> 0:23:10.199
<v Speaker 1>though they may contain more specific information, they use similar

0:23:10.280 --> 0:23:13.159
<v Speaker 1>language because again, they're trying to leverage those principles of

0:23:13.160 --> 0:23:16.520
<v Speaker 1>influence that all humans are vulnerable to. A spear phishing

0:23:16.520 --> 0:23:19.000
<v Speaker 1>attack could take the form of an email claiming to

0:23:19.000 --> 0:23:22.800
<v Speaker 1>contain a security patch or a system update that supposedly

0:23:23.040 --> 0:23:26.000
<v Speaker 1>a company wide policy. The email would claim to guide

0:23:26.040 --> 0:23:29.160
<v Speaker 1>employees to bringing their computers up to date, but actually

0:23:29.440 --> 0:23:32.240
<v Speaker 1>they would install a malicious piece of software. Are a

0:23:32.320 --> 0:23:36.040
<v Speaker 1>good old friend, you know malware and malware can take

0:23:36.080 --> 0:23:39.320
<v Speaker 1>lots of different forms, but typically with phishing attacks, the

0:23:39.400 --> 0:23:43.480
<v Speaker 1>malware's purpose is to facilitate the transfer of stolen information.

0:23:43.760 --> 0:23:45.879
<v Speaker 1>It might allow a back channel of access to a

0:23:45.960 --> 0:23:49.840
<v Speaker 1>system's computers, you know that backdoor access that allows a

0:23:49.880 --> 0:23:52.560
<v Speaker 1>hacker to take administrative control of a computer. Or it

0:23:52.640 --> 0:23:55.920
<v Speaker 1>might contain a key logger which will record every keystroke

0:23:56.080 --> 0:23:58.960
<v Speaker 1>made on that computer, which is an effective way to

0:23:58.960 --> 0:24:01.320
<v Speaker 1>steal someone's user and aim or password. Or it could

0:24:01.320 --> 0:24:04.240
<v Speaker 1>be lots of other stuff too. Worse yet, it could

0:24:04.320 --> 0:24:06.639
<v Speaker 1>contain a file or a link to a page that

0:24:06.640 --> 0:24:10.240
<v Speaker 1>would take advantage of a zero day exploit. This is

0:24:10.240 --> 0:24:13.879
<v Speaker 1>a vulnerability that exists in some form of software or

0:24:13.960 --> 0:24:17.920
<v Speaker 1>operating system that has yet to have been published. It's

0:24:18.040 --> 0:24:21.640
<v Speaker 1>very possible that the entity that made the software has

0:24:21.720 --> 0:24:25.000
<v Speaker 1>no way of knowing that it even exists. Zero day

0:24:25.040 --> 0:24:28.200
<v Speaker 1>exploits are incredibly valuable to hackers. If you find one

0:24:28.359 --> 0:24:30.960
<v Speaker 1>and you know that it hasn't been published, then you

0:24:31.040 --> 0:24:33.280
<v Speaker 1>know that you have a really good chance of that

0:24:33.400 --> 0:24:36.639
<v Speaker 1>zero day exploit having a huge impact if you wrap

0:24:36.680 --> 0:24:39.800
<v Speaker 1>it in some other attack, So you could compromise a

0:24:39.840 --> 0:24:42.920
<v Speaker 1>target computer or an entire system, and you give an

0:24:42.960 --> 0:24:47.520
<v Speaker 1>attacker access to that machine or the entire network that

0:24:47.560 --> 0:24:50.200
<v Speaker 1>machine is connected to, at least as far as the

0:24:50.240 --> 0:24:52.000
<v Speaker 1>target would be able to access. And then if you

0:24:52.040 --> 0:24:55.800
<v Speaker 1>had escalation software in there, you can even escalate so

0:24:55.840 --> 0:25:00.240
<v Speaker 1>that you elevate the the status to admin levels test

0:25:00.320 --> 0:25:03.359
<v Speaker 1>that gives you unfettered access to the system. The spear

0:25:03.400 --> 0:25:06.600
<v Speaker 1>phishing attack might look like it came from another employee

0:25:06.640 --> 0:25:09.680
<v Speaker 1>requesting access to certain types of information. It could look

0:25:09.720 --> 0:25:12.879
<v Speaker 1>like it came from a finance department saying, we need

0:25:12.920 --> 0:25:16.200
<v Speaker 1>you to pay this uh this invoice, so just give

0:25:16.280 --> 0:25:20.080
<v Speaker 1>me your your information here. The larger the organization the

0:25:20.119 --> 0:25:22.399
<v Speaker 1>easier it is to slip something like this through, because

0:25:22.440 --> 0:25:24.960
<v Speaker 1>it's not likely that everyone's going to know everyone else.

0:25:25.680 --> 0:25:28.600
<v Speaker 1>The smaller the organization, the more you might say, I'm

0:25:28.640 --> 0:25:30.720
<v Speaker 1>just gonna walk over to Sue's desk and find out

0:25:30.760 --> 0:25:33.080
<v Speaker 1>if Sue actually sent me this email, and that would

0:25:33.080 --> 0:25:38.399
<v Speaker 1>obviously the work against the the intent of the hacker. Next,

0:25:38.480 --> 0:25:40.199
<v Speaker 1>I'm going to share a whale of a tail with

0:25:40.240 --> 0:25:43.639
<v Speaker 1>you me, lads, but first let's take another quick break

0:25:43.800 --> 0:25:54.520
<v Speaker 1>to thank our sponsor. Okay, so we've defined fishing, and

0:25:54.520 --> 0:25:58.600
<v Speaker 1>we define spear fishing, but what is whaling. Whaling refers

0:25:58.640 --> 0:26:01.879
<v Speaker 1>to phishing attacks that are then more specific than spear fishing.

0:26:02.040 --> 0:26:06.320
<v Speaker 1>These attacks target high ranking executives the the whales, or

0:26:06.320 --> 0:26:09.320
<v Speaker 1>they might be high ranking members of an organization. These

0:26:09.320 --> 0:26:12.600
<v Speaker 1>targets have the most potential access to an organization, and

0:26:12.640 --> 0:26:15.399
<v Speaker 1>it's confidential information, so they have a very high value

0:26:15.440 --> 0:26:18.359
<v Speaker 1>attached to them. The attacker stands to gain the most

0:26:18.600 --> 0:26:23.480
<v Speaker 1>from compromising that kind of target. Also, some of them

0:26:23.600 --> 0:26:27.360
<v Speaker 1>are really really not computer savvy, and as such they

0:26:27.359 --> 0:26:31.000
<v Speaker 1>can fall for tricks way too easily. I say this

0:26:31.280 --> 0:26:34.040
<v Speaker 1>having met a lot of executives who seem to have

0:26:34.160 --> 0:26:38.960
<v Speaker 1>only a cursory understanding of how technology works. Uh. As

0:26:39.160 --> 0:26:43.320
<v Speaker 1>they age out of leadership positions, then we see a

0:26:43.359 --> 0:26:45.000
<v Speaker 1>little bit less of that. But we always got to

0:26:45.040 --> 0:26:48.919
<v Speaker 1>remember that typically leadership tends to be older, you know,

0:26:49.320 --> 0:26:53.959
<v Speaker 1>than your rank and file employee, and because technology changes

0:26:54.040 --> 0:26:57.520
<v Speaker 1>so quickly, it's very possible for the older members of

0:26:57.560 --> 0:27:01.280
<v Speaker 1>any group to have less knowledge about the most current

0:27:01.800 --> 0:27:06.200
<v Speaker 1>and potentially most dangerous uses of tech. So whaling again

0:27:06.240 --> 0:27:09.280
<v Speaker 1>follows similar tactics as phishing and spear fishing. It could

0:27:09.320 --> 0:27:11.840
<v Speaker 1>be a much more specific message designed to give the

0:27:11.840 --> 0:27:14.919
<v Speaker 1>best possible chance for a successful hit, but otherwise it's

0:27:14.960 --> 0:27:17.240
<v Speaker 1>pretty much the same as what we've already covered, So

0:27:17.240 --> 0:27:19.600
<v Speaker 1>I'm not gonna waste time rehashing what I've already said.

0:27:19.680 --> 0:27:24.440
<v Speaker 1>Just remember that the specificity I talked about earlier will

0:27:24.480 --> 0:27:29.120
<v Speaker 1>be even more so for whaling. You will have messages

0:27:29.200 --> 0:27:32.120
<v Speaker 1>that call out the executive by name. It might use

0:27:32.280 --> 0:27:35.440
<v Speaker 1>names of people the executive actually knows. It might even

0:27:35.480 --> 0:27:38.200
<v Speaker 1>use a spoofed email address so it seems like it's

0:27:38.200 --> 0:27:42.040
<v Speaker 1>coming from someone the person knows. Of course, the closer

0:27:42.119 --> 0:27:45.480
<v Speaker 1>the friendship, the more you run the risk of not

0:27:45.760 --> 0:27:50.280
<v Speaker 1>sounding like that person, which could set off red flags

0:27:50.440 --> 0:27:53.560
<v Speaker 1>in someone's mind. They might say, huh, soon never talks

0:27:53.560 --> 0:27:56.399
<v Speaker 1>to me like this an email that would end up

0:27:56.400 --> 0:27:58.840
<v Speaker 1>being an issue, But otherwise you have a much greater

0:27:59.000 --> 0:28:03.800
<v Speaker 1>chance of getting a succes us. As always, you should

0:28:03.880 --> 0:28:07.000
<v Speaker 1>use critical thinking whenever you get a message. It's best

0:28:07.040 --> 0:28:10.440
<v Speaker 1>to do so. And while I've focused on email again,

0:28:10.640 --> 0:28:13.439
<v Speaker 1>those phishing attacts could come through other channels such as

0:28:13.480 --> 0:28:18.320
<v Speaker 1>instant messaging or similar communication channels, or even through spoofed websites.

0:28:18.440 --> 0:28:21.800
<v Speaker 1>So using critical thinking and just paying attention can really

0:28:21.840 --> 0:28:24.200
<v Speaker 1>save you a lot of heart heartache in the long run.

0:28:24.240 --> 0:28:27.760
<v Speaker 1>So here's some basic rules you should follow. First, try

0:28:27.800 --> 0:28:30.280
<v Speaker 1>to make sure an incoming message is in fact from

0:28:30.280 --> 0:28:33.719
<v Speaker 1>a legitimate source, particularly if there's an attachment to the

0:28:33.760 --> 0:28:37.199
<v Speaker 1>email or if it's asking you to hand over information.

0:28:37.359 --> 0:28:40.320
<v Speaker 1>That might involve digging a little deeper if the attacker

0:28:40.360 --> 0:28:43.720
<v Speaker 1>bothered to forge an email field, so if they forge

0:28:43.800 --> 0:28:46.360
<v Speaker 1>that from field, then you might need to check the

0:28:46.400 --> 0:28:48.560
<v Speaker 1>source code just to make sure that in fact it

0:28:48.680 --> 0:28:52.040
<v Speaker 1>is legitimate. And then you might even ask like, well,

0:28:52.040 --> 0:28:54.200
<v Speaker 1>why are they asking for this information and why should

0:28:54.240 --> 0:28:56.520
<v Speaker 1>it be done over email? That's not necessarily the most

0:28:56.560 --> 0:29:00.000
<v Speaker 1>secure way. In fact, You should really never send confident

0:29:00.080 --> 0:29:05.280
<v Speaker 1>ential information like user names, passwords, credit card information, wire

0:29:05.320 --> 0:29:08.640
<v Speaker 1>transfer information, anything like that over email or an instant

0:29:08.680 --> 0:29:11.959
<v Speaker 1>message system because most of the time those are not secure.

0:29:12.040 --> 0:29:14.920
<v Speaker 1>They're not a lot of them are not encrypted. So

0:29:15.000 --> 0:29:18.200
<v Speaker 1>even if the person contacting you is completely legitimate, if

0:29:18.680 --> 0:29:21.000
<v Speaker 1>they are on the up and up, you totally trust them.

0:29:21.240 --> 0:29:25.000
<v Speaker 1>They're not gonna do anything to to to mess with

0:29:25.080 --> 0:29:28.960
<v Speaker 1>you the channel. If you're using a channel that's unencrypted,

0:29:29.000 --> 0:29:32.400
<v Speaker 1>someone else could potentially get hold of that information. So

0:29:32.680 --> 0:29:35.160
<v Speaker 1>it may even be that a third party could get

0:29:35.240 --> 0:29:37.400
<v Speaker 1>hold of this information. It's just not a smart move

0:29:37.480 --> 0:29:40.680
<v Speaker 1>to send that kind of stuff over email or instant messager,

0:29:40.960 --> 0:29:44.080
<v Speaker 1>and most legitimate communication will never require you to send

0:29:44.080 --> 0:29:46.880
<v Speaker 1>in sensitive info over email. Rather, you would have to

0:29:47.160 --> 0:29:50.120
<v Speaker 1>visit a legit website that's verified and secure. You look

0:29:50.160 --> 0:29:52.840
<v Speaker 1>for that little lock in the U r L bar,

0:29:53.000 --> 0:29:55.680
<v Speaker 1>and you make sure that the website you go to

0:29:55.800 --> 0:29:59.120
<v Speaker 1>actually belongs to the company or entity that it's supposed

0:29:59.120 --> 0:30:02.560
<v Speaker 1>to belong to before fill anything out. Third, if you're

0:30:02.560 --> 0:30:05.280
<v Speaker 1>in a company or organization and you receive a message

0:30:05.320 --> 0:30:08.120
<v Speaker 1>that seems hinky and it's catered to you or to

0:30:08.160 --> 0:30:11.040
<v Speaker 1>your company, you should probably let someone in I T

0:30:11.200 --> 0:30:13.080
<v Speaker 1>know about it so that they can be on the

0:30:13.080 --> 0:30:16.560
<v Speaker 1>lookout and perhaps issue a company wide alert. Because even

0:30:16.600 --> 0:30:19.720
<v Speaker 1>if you don't fall for this, if it's a spear

0:30:19.760 --> 0:30:22.680
<v Speaker 1>fishing attack that's targeting people who belong to the same

0:30:22.760 --> 0:30:25.120
<v Speaker 1>organization you do or the same company you work for,

0:30:25.760 --> 0:30:28.120
<v Speaker 1>all it takes is a couple, maybe even as few

0:30:28.160 --> 0:30:31.680
<v Speaker 1>as one positive hits to make a lot of damage.

0:30:32.120 --> 0:30:36.480
<v Speaker 1>So if you notice something, you say something, it gives

0:30:36.480 --> 0:30:40.640
<v Speaker 1>you the best chance to not have your company or

0:30:40.760 --> 0:30:44.080
<v Speaker 1>organization fall victim to these kind of attacks. This is

0:30:44.160 --> 0:30:47.160
<v Speaker 1>really serious business. So let's take another look at the

0:30:47.280 --> 0:30:50.480
<v Speaker 1>U S. D n C phishing attacks in twenty sixteen

0:30:50.480 --> 0:30:54.800
<v Speaker 1>that I mentioned earlier. So what actually happened in those attacks. Well,

0:30:54.840 --> 0:30:57.520
<v Speaker 1>according to a joint report from the Department of Homeland

0:30:57.520 --> 0:31:01.600
<v Speaker 1>Security and the FBI, two groups which the report labels

0:31:01.680 --> 0:31:06.040
<v Speaker 1>a P twenty eight and APT twenty nine, breached the

0:31:06.120 --> 0:31:09.200
<v Speaker 1>d n C servers through phishing attacks. APT, by the way,

0:31:09.240 --> 0:31:13.800
<v Speaker 1>stands for Advanced Persistent threat. The first attack started in

0:31:13.840 --> 0:31:17.520
<v Speaker 1>the summer of The group behind the attack was APT

0:31:17.800 --> 0:31:21.120
<v Speaker 1>twenty nine. The attackers sent emails to more than one

0:31:21.160 --> 0:31:25.120
<v Speaker 1>thousand different addresses attached to the d n C, and

0:31:25.160 --> 0:31:28.560
<v Speaker 1>the messages contained malware attachments. They were posing as a

0:31:28.600 --> 0:31:31.600
<v Speaker 1>normal file. It looked like an innocent file. Opening the

0:31:31.640 --> 0:31:35.320
<v Speaker 1>file would install the malware on the target machine. The

0:31:35.400 --> 0:31:40.880
<v Speaker 1>malware established an encrypted communication channel between the compromise systems

0:31:41.160 --> 0:31:45.600
<v Speaker 1>and APT twenty nine. The malware also could escalate privileges,

0:31:45.880 --> 0:31:48.520
<v Speaker 1>meaning the malware was able to trick computers into giving

0:31:48.520 --> 0:31:51.400
<v Speaker 1>the attackers admin level access to the system so they

0:31:51.400 --> 0:31:55.640
<v Speaker 1>could steal information send it back to their own computers

0:31:55.680 --> 0:31:59.200
<v Speaker 1>over this encrypted channel of communication, and because of this

0:31:59.440 --> 0:32:02.680
<v Speaker 1>they were largely undetected for a while. The second attack

0:32:02.800 --> 0:32:06.400
<v Speaker 1>happened in that was a P twenty eight. They sent

0:32:06.440 --> 0:32:08.880
<v Speaker 1>out an email to a large number of people in

0:32:08.960 --> 0:32:12.120
<v Speaker 1>the d n C. The email posed as an organization

0:32:12.160 --> 0:32:15.560
<v Speaker 1>wide policy that would require users to reset their passwords,

0:32:15.560 --> 0:32:18.480
<v Speaker 1>saying passwords have expired. You need to go and follow

0:32:18.520 --> 0:32:22.320
<v Speaker 1>this link and reset your password. So they would go

0:32:22.400 --> 0:32:24.280
<v Speaker 1>to a link and that led to a website that

0:32:24.360 --> 0:32:26.240
<v Speaker 1>was made to look like it was an official d

0:32:26.360 --> 0:32:28.920
<v Speaker 1>NC site, but in fact it was a phishing site,

0:32:29.200 --> 0:32:31.480
<v Speaker 1>so they would guide users to enter their user names

0:32:31.480 --> 0:32:34.960
<v Speaker 1>and their passwords and a new password. Ostensibly so that

0:32:35.040 --> 0:32:38.560
<v Speaker 1>they could reset their passwords, but in reality, the hackers

0:32:38.600 --> 0:32:42.000
<v Speaker 1>were gathering log and credentials and they were just shipp

0:32:42.040 --> 0:32:47.040
<v Speaker 1>shipping them straight to APT. The investigation into those attacks

0:32:47.080 --> 0:32:49.600
<v Speaker 1>is still ongoing, but from what we know, it seems

0:32:49.640 --> 0:32:54.200
<v Speaker 1>pretty certain the attackers were Russian civilian and military intelligence services.

0:32:54.800 --> 0:32:58.960
<v Speaker 1>So you have a group of Russian hackers targeting a

0:32:59.120 --> 0:33:04.080
<v Speaker 1>United States political parties UH systems, and that's a big

0:33:04.240 --> 0:33:07.440
<v Speaker 1>scary thing. No matter what country you live in or

0:33:07.480 --> 0:33:12.080
<v Speaker 1>what country uh you know, no matter which countries are involved,

0:33:12.160 --> 0:33:14.240
<v Speaker 1>this kind of attack is a serious thing where one

0:33:14.280 --> 0:33:19.800
<v Speaker 1>country is trying to influence the political outcome of another country.

0:33:19.920 --> 0:33:23.120
<v Speaker 1>I don't care who you are. That's terrifying. The United States,

0:33:23.640 --> 0:33:28.320
<v Speaker 1>by the way, has done not necessarily cyber crime kind

0:33:28.360 --> 0:33:31.960
<v Speaker 1>of stuff like this, but the US certainly has a

0:33:32.040 --> 0:33:35.560
<v Speaker 1>long history of trying to influence other nations and their

0:33:35.560 --> 0:33:39.920
<v Speaker 1>political proceedings. So I'm not saying the US is innocent

0:33:39.920 --> 0:33:42.800
<v Speaker 1>of those kind of things either, But it is terrifying

0:33:42.840 --> 0:33:46.200
<v Speaker 1>to look at the way that you can actually leverage

0:33:46.400 --> 0:33:50.560
<v Speaker 1>human psychology and have a big impact like this, And honestly,

0:33:50.600 --> 0:33:52.720
<v Speaker 1>I think that's the most troubling thing about fishing attacks

0:33:52.720 --> 0:33:55.920
<v Speaker 1>because they don't have to be sophisticated. There's no need

0:33:55.960 --> 0:33:58.960
<v Speaker 1>to craft a super tricky code. You don't have to

0:33:59.000 --> 0:34:03.720
<v Speaker 1>sit there and secretly infiltrate a computer system. Phishing works

0:34:04.120 --> 0:34:07.959
<v Speaker 1>not because of the technology. I mean technology facilitates it.

0:34:07.960 --> 0:34:11.760
<v Speaker 1>It makes it easier to steal information. But phishing works

0:34:11.840 --> 0:34:14.680
<v Speaker 1>because of the way we humans work. It works because

0:34:14.680 --> 0:34:17.959
<v Speaker 1>we're fallible. We can be tricked, we can be influenced.

0:34:18.280 --> 0:34:21.000
<v Speaker 1>It shows yet again that no matter how secure a

0:34:21.080 --> 0:34:24.440
<v Speaker 1>system is, no matter what technology you have put in place,

0:34:25.040 --> 0:34:27.440
<v Speaker 1>the system is really only as good as the people

0:34:27.560 --> 0:34:30.560
<v Speaker 1>who have access to it. If you design the world's

0:34:30.680 --> 0:34:35.000
<v Speaker 1>most secure bank vault door and it has biometrics and

0:34:35.440 --> 0:34:37.959
<v Speaker 1>voice activation and all this kind of stuff where only

0:34:38.239 --> 0:34:41.520
<v Speaker 1>a select few are able to ever access it, and

0:34:41.560 --> 0:34:44.279
<v Speaker 1>then I leave that door open while I dash off

0:34:44.320 --> 0:34:46.360
<v Speaker 1>to go grab lunch, it doesn't do you any good.

0:34:46.719 --> 0:34:51.800
<v Speaker 1>I have practiced very very very bad security protocol. Phishing

0:34:51.840 --> 0:34:55.440
<v Speaker 1>works because we humans will often take these mental shortcuts

0:34:55.640 --> 0:34:58.279
<v Speaker 1>and we won't use critical thinking. And it doesn't need

0:34:58.320 --> 0:35:00.880
<v Speaker 1>to work every single time. In fact, pending upon the attack,

0:35:00.920 --> 0:35:03.440
<v Speaker 1>it may need to only work once. So if there

0:35:03.440 --> 0:35:06.440
<v Speaker 1>are ten thousand employees of a company, and you just

0:35:06.520 --> 0:35:09.680
<v Speaker 1>need just one of them to click on a malicious attachment.

0:35:09.960 --> 0:35:13.000
<v Speaker 1>That means all you need is a point zero one

0:35:13.080 --> 0:35:17.320
<v Speaker 1>percent success rate. It does not have to be great,

0:35:18.080 --> 0:35:21.520
<v Speaker 1>it just has to work once. So it's no surprise

0:35:21.560 --> 0:35:23.640
<v Speaker 1>that there's so many phishing attacks out in the wild.

0:35:23.960 --> 0:35:25.960
<v Speaker 1>They get results, and they don't need a lot of

0:35:25.960 --> 0:35:27.799
<v Speaker 1>people to fall for them to be effective. That's all

0:35:28.040 --> 0:35:30.040
<v Speaker 1>Also why there's a lot of crappy ones out there,

0:35:30.080 --> 0:35:34.520
<v Speaker 1>because why put in the effort to design something really,

0:35:34.560 --> 0:35:38.000
<v Speaker 1>really good If you can still get hits with something

0:35:38.040 --> 0:35:40.440
<v Speaker 1>that's crappy. That will save you time and effort. So

0:35:40.560 --> 0:35:42.399
<v Speaker 1>just go ahead send the crappy thing out. You won't

0:35:42.440 --> 0:35:46.560
<v Speaker 1>get quality hits, but you'll still get hits. To defeat

0:35:46.600 --> 0:35:50.120
<v Speaker 1>phishing scams, we can institute different protocols and protections to

0:35:50.120 --> 0:35:52.480
<v Speaker 1>help weed out spam emails before they ever get to

0:35:52.520 --> 0:35:54.840
<v Speaker 1>a user, and obvious scams that kind of thing. We

0:35:54.880 --> 0:36:00.360
<v Speaker 1>can blacklist certain uh I P addresses, but ultimately we

0:36:00.440 --> 0:36:03.560
<v Speaker 1>have to rely on people resisting those attempts to influence

0:36:03.600 --> 0:36:06.080
<v Speaker 1>them and use a bit of critical thinking. Now. I

0:36:06.080 --> 0:36:07.880
<v Speaker 1>know I've talked a lot about critical thinking over the

0:36:07.960 --> 0:36:10.160
<v Speaker 1>last two weeks, I'm gonna give it a rest. I'm

0:36:10.160 --> 0:36:12.360
<v Speaker 1>gonna switch gears for the rest of this week, sort of.

0:36:12.880 --> 0:36:15.360
<v Speaker 1>I always try to use critical thinking whenever I'm putting

0:36:15.360 --> 0:36:18.080
<v Speaker 1>a show together, so there is some going on in

0:36:18.080 --> 0:36:20.320
<v Speaker 1>the back end, but I'm not gonna harp on about

0:36:20.360 --> 0:36:23.680
<v Speaker 1>it anymore for the rest of this week. Instead, we're

0:36:23.719 --> 0:36:28.919
<v Speaker 1>going to talk about speech recognition, natural language processing, and

0:36:29.520 --> 0:36:34.160
<v Speaker 1>voice assistant slash virtual assistant slash. It's hard to come

0:36:34.239 --> 0:36:35.560
<v Speaker 1>up with a name for them, but you know, I'm

0:36:35.560 --> 0:36:39.480
<v Speaker 1>talking about your series, your Alexas, your Google assistants, that

0:36:39.560 --> 0:36:41.320
<v Speaker 1>kind of thing. So that's where we're going to concentrate

0:36:41.480 --> 0:36:43.320
<v Speaker 1>on for the rest of this week. If you guys

0:36:43.360 --> 0:36:46.320
<v Speaker 1>have any suggestions for future episodes of Tech Stuff, whether

0:36:46.360 --> 0:36:50.160
<v Speaker 1>it's a specific technology, maybe it's a policy relating to tech.

0:36:50.600 --> 0:36:53.719
<v Speaker 1>Maybe it's a company or a person in technology. Maybe

0:36:53.760 --> 0:36:55.880
<v Speaker 1>there's someone you want me to interview or have on

0:36:55.920 --> 0:36:59.000
<v Speaker 1>as a special guest, Please let me know. Send me

0:36:59.040 --> 0:37:02.000
<v Speaker 1>a message. My email address for this show is tech

0:37:02.080 --> 0:37:05.680
<v Speaker 1>Stuff at how stuff works dot com, or you can

0:37:05.760 --> 0:37:08.600
<v Speaker 1>drop me a line on Facebook or Twitter. The handle

0:37:08.680 --> 0:37:12.200
<v Speaker 1>for both of those is tech Stuff hs W. Don't

0:37:12.239 --> 0:37:15.040
<v Speaker 1>forget to follow us on Instagram and I'll talk to

0:37:15.040 --> 0:37:24.280
<v Speaker 1>you again really soon. For more on this and thousands

0:37:24.320 --> 0:37:36.560
<v Speaker 1>of other topics, because it how stuff works. Dot com