Speaker A: This program is brought to you by Resonance 104.4 FM. If you like what you hear and want to support our work, please make a donation at fundraiser.resonance.fm.
Speaker C: Hello and welcome to Password from the man who likes technological gadgets, sailing his boat, and a glass of red wine. I’m Peter Warren, but then you know that already if you follow me on social media. And I know how dangerous it can be to share personal information, and that leaves me open to hacking, ID theft, and manipulation. As we launch ourselves into another new year, my prediction is that because we shed data, both businesses and individuals, at the same rate as we do skin, that this will be an annus horribilis for cybercrime. Already in the first few days of 2019, there has been a massive data breach at the German Parliament, which now apparently has been discovered to be the work of a teenager. Last year, cybercrime’s or incidents related to it never seem to let up. In November, two young men were sent to jail for 12 and 8 months respectively for breaking into 77 million TalkTalk customer details. At the end of the month, the hotel group Marriott admitted that it had been hit by an attack in which 500 million customer records were lost. Marriott now says it was being pessimistic Only 383 million records, including 5 million undecrypted password numbers and 20 million encrypted ones, were lost. December paled into insignificance by comparison, as it saw the chemist chain Well Pharmacy in the USA apologizing to 24,000 employees after a breach lost their personal data, including payrolls. I could go on. In the next hour, we’ll be discussing why many experts think we’re heading for an epidemic of online theft and why most of us still don’t seem to care about our personal privacy and security. We love Facebook and Google, Uber and Airbnb, and we love to shop online, but our data trails leave us vulnerable. The problem with this is that it can’t go on. Keep losing data at the rate we are and being hit by hacking attacks, and the high-tech edifice that makes up our world will come crumbling down, and promised breakthroughs like AI and automated vehicles will not happen because we will not be able to trust the integrity of the systems. Writer Jamie Bartlett’s been at Stanford University in California’s Silicon Valley for a dramatic demonstration of how social media strips us bare.
Speaker A: Oh yeah, it’s amazing, isn’t it? And it’s, it’s just based on, on, with enough data and enough correlations between different data points, you learn these new things about people. And that’s why I think a lot of us find it a little bit odd. You know, I went in to visit Michal Kosinski, who’s one of the pioneers. He’s a professor at Stanford University. He’s one of the pioneers of this particular technique called psychographic. Targeting, which is where you try to build up a psychological profile of people based on the things they’ve liked on Facebook. So I go in there and I fill in all of my, you know, I enter all of my likes that I’ve clicked on over the years on Facebook, and it spits out a profile of me based on whether I’m open or conscientious or neurotic, and it gives me scores for each of those. And also says the algorithms thinks that you’re ‘You’re not religious, but if you were religious, you’re most likely to have been Catholic.’ Which is exactly right. You know, I went to Catholic school all of my life. I went to a Catholic comprehensive school in Kent. But nothing I’d clicked on Facebook had anything to do with Catholicism. I mean, apart from maybe The Sopranos or something. And yet it was simply based on pattern recognition that people who’d liked X tended to be Y. And that’s the thing that I think people don’t understand sometimes about this. Obviously, if your Tesco shopping habit shows consistently that you’re buying Tesco’s finest, you’re obviously a man of great distinction and taste. But that’s easy to do. What’s the interesting thing here is that it can then say, we also think you’re aged between this and this, and that you care about this issue and you vote for this party. And while it often gets things wrong, on the whole, it’s pretty damn accurate. And again, getting more accurate because you know how much more data we’re going to be producing in the years ahead, right? I mean, it’s increasing all the time, and so you’ve got to assume that the models are going to get better with it.
Speaker C: And as the algorithms compile ever richer files on our behavior, so those who want to track us find it’s even easier. They know just what we want. So They can load their scam emails with exactly the right bait to make us click because they’ve been researching us. But it’s not a game, it’s a crime. It’s true that convicted criminals like the TalkTalk Two usually receive sentences that are much shorter and more lenient than the real-life criminals who physically burgle people’s homes, ram raid cash machines, or use threats to blackmail people. And yet this doesn’t seem fair, for as Professor Angela Sassi from the University of London tells me, cybercrime is never victimless.
Speaker D: Even when the victims are refunded by their banks, because there is an element of that the bank actually didn’t check, for instance, that where the bank should have caught that the payee was actually not the one associated with the bank account number or something, which they’re now supposed to have to do. Even if you get refunded, there’s still an emotional cost to pay. Very often it takes a lot of time and effort to go through the process and get it back. But also really emotionally, people often feel it’s basically when you’re a victim of crime. There really is that sort of emotional cost you have to pay. Loss of trust, you know, that you suddenly don’t trust yourself anymore to be, to be an effective, to be able to operate in that environment.
Speaker C: That’s one of the fascinating things, isn’t it? We’re only just beginning to realize this is that perception of being stupid. It’s one thing that we feel.
Speaker D: Yeah. And then it also means that often victims really don’t report this, you know, they’re so ashamed or embarrassed that they suffer in silence. That they don’t actually go to the police when they’ve lost significant amounts of money, or people even end up, they don’t, killing themselves rather than telling their family that they’ve lost the money, that they’ve been scammed and lost the money. It can be really, the cost of this can be really, really horrible.
Speaker C: And then there is also another concomitant symptom too. Quite often people feel paranoid, they feel as though they’ve been targeted, they feel as though they’ve been watched.
Speaker D: And that can sometimes happen as a result of an experience like that, that people then really question everyone every approach and every move. And then of course that can then also mean you can’t really effectively work, you know, you can’t really effectively function in today’s digital environment anymore.
Speaker C: So we’re beginning to see some things happening that, I don’t know, I suppose probably it’s because we’ve been online now for 20 years and some of these symptoms are beginning to come through. Just one other really interesting thing. According to a lot of the people that we’ve spoken to, the police and also cybersecurity companies, There’s a massive rise in cybercrime, particularly this Christmas, according to one of the cybersecurity companies, it’s up 65%. Is this now the crime of choice for the criminal?
Speaker D: Yeah, if some of them have the success, I mean, clearly that basically encourages more imitators to come in on this game. It is quite interesting, a few years ago, when I spoke to a police officer, he said actually a lot of the people involved, if they weren’t doing this, they would be like driving pizza for Domino’s. And they just think it’s nicer to sit inside in the bedroom and do things from the keyboard rather than be out in all weathers. But clearly it’s also quite a sophisticated market already where there’s division of labor and specialization. And some people just sell the the data, some people sell the tools, and some basically monetize. And in that environment, yeah, it’s just seen as quite a promising industry. And so I think it’s also something we’ve seen that in economically weak areas where there aren’t a lot of alternatives. So for instance, in parts of Romania or parts of Nigeria where you have relatively skilled young people who can’t get a job or a decent well-paid job without connections, you know, just end up really getting into this type of crime because it’s the only, the only thing they can do to, to earn a decent living.
Speaker C: And I suppose to take that point that you make about all of these different little niches in the industry, if you’re just taking people’s names and addresses or taking people’s card details, you don’t see it as being as wrong as perhaps defrauding them directly. You don’t see that as wrong. You just see that as it’s a job getting some data. You’re not doing something. You’re not actually perpetrating the criminal act.
Speaker D: Yeah, I’m sure that some of the people do that tell themselves it’s not that. It’s not, by and large, not. So they tell themselves, you know, that the victims are just stupid and only have themselves to blame as a way of justifying. But I think, again, that’s no different than it is with other times, with other forms of crimes and criminals. You know, if you spoke to an experienced law enforcement officer, they would tell you that they often have those kind of excuses.
Speaker C: According to a policeman that we spoke to, he said that this information may have come from your own university. He said that there are more people now, more children or more youngsters involved in hacking than there are having underage sex, underage drinking, underage drugs or smoking.
Speaker D: I’m not an expert in crime science, so I haven’t seen those numbers, but yeah.
Speaker C: Well, that was in the University of London Millennial Cohort. Study.
Speaker D: Okay, if they’ve got it from there, then that is a good source.
Speaker C: It’s fascinating, isn’t it, that I suppose it’s almost a reflection of how our society’s changing. I mean, those would have been considered to be quite risqué activities, but now hacking’s taken over.
Speaker D: Yeah, but the tragic thing about this is if you have— they’re often youngsters who do that, often don’t think about the consequences. They think it’s exciting. And yes, as you said, there is a bit of frisson, sort of some people just love crime stories and crime capers. But if you cross the line, then it’s very tragic that somebody who may actually be quite smart and have some good technical skills can ruin their life chances by once they’ve committed a crime, when they’re then caught and convicted, they’re actually shutting off what potentially could be a quite lucrative a lucrative career in IT in general or in cybersecurity in particular. Once you’ve actually got a criminal record, those skills may not really be as— you know, you can’t really make an honest living from it anymore.
Speaker C: Diverting youngsters from this potential slippery slope is the job of Police Officer Max Bruce of the City of London force, which specialises in financial crimes. He tells me that half of all the fraud and theft his force investigates is now committed online. And he has this advice on how to avoid falling victim to the scammers.
Speaker B: It’s about taking your time. There’s a really good campaign at the moment called Take Five, which is all about this. And when you get that sort of unsolicited communication, you just take a step back, you think for a minute, you know, is this reasonable? Is this normally how I would do my business or I would buy my products? And just think, you know, does it look legitimate? Does the price look right? And then just going to that site via a trusted source, a trusted method. And it’s not just online. I think people need to be aware that, you know, a text message can be spoofed to look like a trusted company, or a telephone number can be spoofed again to look as if it’s coming from a genuine organisation. And thinking, no, you know, if you do want to engage with that company, You take the time, you contact them via, you know, a source that you know, you trust, be that via email or telephone. And sort of just taking that time is really important.
Speaker C: I mean, that’s, that’s it, isn’t it? Because nobody sits there and thinks— because the word is serendipity, isn’t it? The occurrence and development of events by chance in a happy or beneficial way. And there you are, suddenly in your email queue comes the news of that thing that you really want. That’s in a sense, that thing that is, as you say, too good to be true, isn’t it? Because they are also taking advantage of deliveries. So they’re sending emails to you saying, oh, here’s news about your delivery from Amazon. Yep.
Speaker E: Okay.
Speaker B: So, I mean, that would definitely be then sort of the next step, I guess, that we see within the online shopping fraud is, you know, once you have bought that product, you will then, like I say, be expecting a delivery to come afterwards. So they can exploit sort of the UPS and the delivery and the Royal Mail saying, you know, you’ve had a delivery, a failed delivery attempt or something. Click, click on the link to see, uh, you know, update of your status or to rebook a delivery at a time that suits you. And that’s the sort of thing that people may think, oh, I don’t remember purchasing something, or they may have already purchased something and be expecting it. So, you know, people will, will click on it out of curiosity a lot of the time. So it’s about, again, taking your time, thinking, actually, is this Is this a reasonable request? Is this a company that I’d be expecting a delivery from? And maybe logging in via another method as opposed to just clicking on that link, because then, you know, it can take you to a fraudulent website where you can put in password details or maybe payment details, and that is really what they’re after.
Speaker C: I mean, that, that is the big key, isn’t it? Because people should be aware of the fact that in their email queues they might get lots and lots of emails to do with the bank that they aren’t a customer of. And essentially what the criminals are doing is just sending out these blanket emails, hoping that they will go to a person who is the customer of that bank, and they’ll open that bank because they think it relates to them. So that point that you’re making about going out there and actually going to your bank, using your credentials to log in, finding the truth— that’s the important thing, isn’t it?
Speaker B: Yes, I mean, certainly with your bank, for example, they will sort of target the large banks, and, you know, there’s a good chance if you send an email out to enough people, you will hit enough of the right customers just by chance. But so a lot of people will look at that and think it’s clearly a fraudulent email, but a lot of people may think that’s actually from their bank. But again, think, why would your bank be contacting you? Is this normally how you do the business? And then think how you would contact your bank if you needed to. So use something like a trusted number that you would find on the back of your bank card, for example, rather than using the number that they may have provided within the email where they can make it look very official looking, but it is in fact a fraudulent email. It’s about that moment, isn’t it? And just sort of, like I said, taking a little step back and just thinking. It doesn’t have to be for long, but just sort of keep, keep your emotions in check and just think, is this legitimate? Is this ‘Is this— does this seem reasonable?’ And, you know, trust your instincts a lot of the time as well. That’s a really key thing that we can do. And just think, you know, ‘Is this normally what I would do?’ And like I say, if it is something that you are expecting, then just finding that trusted method to contact them rather than clicking on a link or calling a number that they provided for you.
Speaker C: Another tactic being deployed besides the microtargeting and social engineering we heard about earlier is to lure victims into giving away their personal data through tapping into current events. Max Bruce again.
Speaker B: Within trends for the criminals, I mean, what we’re seeing a lot of at the moment, a sort of target on the back of news a lot of the times now. So if you hear a story in the news, maybe a data breach comes up quite a lot at the moment, so British Airways, for example, or the Marriott Hotel we’ve just had, or like I say, some sort of delivery company. So they’re trying to exploit those things that we hear about a lot of in the news and we’re almost expecting to come in. So they’re the sort of the lures that they might use, but then also taking that sort of time-sensitive approach, that urgent language which seems to get us. So urgent, expires, immediately. You put those words into an email, it kind of gives that sort of call to action for someone that they must do something. Going into the next year, before the end of the financial year, the taxman will suddenly become a really targeted entity for the fraudsters because people will be expecting those types of emails, but they’ll also have that sort of urgency and need to deal with those sorts of things because they’ll be thinking about their tax returns, etc. So again, it’s really important that we think about how we would contact those entities at this time. So right now, like I say, it’s about Christmas, it’s about products, it’s about deliveries. We may see something in the news and then the criminals will try and exploit those types of things as well.
Speaker C: That’s coming in by email. I presume that email is the favoured method of attack for criminals, but there must be other ways that they’re trying to trap you. Presumably there are some websites that they’ve taken over, things like that.
Speaker B: Yeah, so I mean, email is certainly the most common, but I mean, it should be noted that the telephone is still the most successful for fraudsters. So actually having that sort of personal interaction, I think, is quite important. That kind of create that social engineering environment is really successful for them. So, you know, taking over a website, sort of the example you gave there, but maybe not necessarily taking over, but again, it’s about creating a fraudulent website. Website that looks just like something that you would expect if you were to log in. So how you get to those websites is very much through your emails and through the links. So that still is sort of a key, key enabler, but it’s very much about the impersonation of legitimate entities that is successful.
Speaker C: When you say the telephone is the favored way, what, this is somebody ringing up pretending to be your bank, pretending to be Microsoft? I note that 10 call centres in India, the staff at 10 call centres were arrested a couple of weeks ago for doing that Microsoft scam. Are those the sorts of things you’re talking about?
Speaker B: Yeah, so I mean, certainly with the telephone, yeah, it’s the impersonation of that trusted entity that you might be expecting. So your bank would be one, the taxman, so HMRC, but also we’re seeing a lot of, say, computer software service fraud. Sort of as you were talking about, someone may contact you pretending to be from a well-known computer company saying that they’ve, they’ve noticed that there might be a virus or a problem with your computer and they can fix it for you there and then. What they’ll be trying to do is try and help you and talk you through that, but get you to pay for fixing it for you, but also for you to allow them access to your computer, which then they can use to try and harvest more information and more details and maybe access your bank account. Via there. So they’re trying to get you in many different ways, but it all starts with that impersonation of a trusted and well-known entity.
Speaker C: So once again, then what you do is you say, thank you very much for contacting me, put the phone down and ring the relevant organization if you are concerned and get them out of the loop.
Speaker B: Exactly. Like I say, it’s about, it’s about, you know, don’t just trust, verify. And if you do think there might be something wrong with your computer, or you Seek professional help, speak to a friend, look online about where you can get these sort of computer IT help and that sort of thing. And speak with your friends and family about where they may go to. Do it in your own time when it suits. Don’t be rushed or pressured thinking you have to do something there and then, because they will hit you with a time-sensitive offer or try and get you to think that it has to be done now when it doesn’t. And it’s like I said, it’s really important. Take your time, take a step back, don’t just trust it, verify it, and that will be a major blocker for criminals in lots and lots of different attempts that they make.
Speaker C: Max Bruce from the City of London Police. This is Password with me, Peter Warren, on Resonance FM, and after this you can hear A World in London with DJ Ritu. As we’ve heard, we’re now in a world of smoke and mirrors. Spooks and trolls, fake news, Russian political manipulation, and left- and right-wing information wars. Journalism is in decline, and journalists are too. They are literally being killed at frightening rates, according to articles in December in The Guardian and Washington Post. While in January 2019, already the US Center for International Media has echoed warnings from the EU’s European Center for Press and Broadcasting Freedom of a sustained attack on the media on all continents. So what do we do? We’ve been hearing how our own online habits leave us open to fraudsters. Perhaps you’ve already made a New Year’s resolution to create new passwords for all your online accounts, to make them all different and not easy to guess by anyone who can read social media posts about your pets, your children, or your birthdays. Even with better cybersecurity, it’s frighteningly easy to get hacked. I’ve been looking online for tutorials in how to hack, and I found plenty of easy-to-follow videos like this one, for example.
Speaker F: Hey guys, it’s PC Tutorials here. So this is an updated version on the Command Prompt basic tricks and tips video I made about 3 years ago. Um, I was obviously not that mature then, and I knew what I was talking about, but the way I described it was extremely confusing.
Speaker C: Beginning a career in computer hacking in the 21st century is quite simply child’s play. A basic search on YouTube can turn up any number of tutorials on how to get started, with advice on everything from cracking passwords, targeting individuals, DDoS attacks, attacking websites, and attacking Facebook pages. Some of the tutorials stress the kudos that you can get from classmates when they know of your hacking skills.
Speaker F: Hey guys, it’s me here with another tutorial for you today. Today I’m going to show you guys how to be a computer hacker. Now you’re probably asking, hey, what are the benefits of being a computer hacker?
Speaker C: Well, first of all, it makes you look cooler in front of people, including your friends and family, and also makes people on the internet listen to you. So in this tutorial, I’m going to show you what you can do to be a computer hacker. Enjoy! In the febrile world of the 10-year-old and the teenager, being in touch with your tech confers awesome powers. Uh, how about we go 175? That should work. Okay, so what you’re going to do is put your name in like this to let everybody know that you were the person who edited this.
Speaker F: And not to fuck with you, okay?
Speaker C: To have the life or death of a Facebook page in your hands means you are a magician. Cracking someone’s password in our high-tech world will give you the keys to their life. It’s a teenage trend that is now a serious concern to the police.
Speaker F: This is probably easier now than it’s ever been in history. I think there’s probably this perception that cybercriminals are these hugely technically sophisticated, almost whiz kids doing what they’re doing, building these amazing platforms and tools to help exploit people. But actually, often, whilst at the top end that’s very true, actually, in terms of the general day-to-day big volumes, if anything, the complete opposite is true. There are so many tools that are readily available online that people can download and use for free with very, very limited skill or knowledge, and there are tutorials on YouTube and elsewhere to assist. You don’t have to be particularly tech-savvy to be able to launch some relatively sophisticated attacks using some pretty basic tools to trick people.
Speaker C: As we heard in last month’s Password, research into 18,000 millennials by University College London found that 7% of 14-year-olds have admitted to hacking. More than the 3% who had smoked and the 6% who had taken drugs. Hacking is street cool, and the police now have to head it off. Hackers who follow these basic guidelines are low down in the pecking order of the cybercriminal world. Script kiddies, manipulated by the Mr. Bigs—and they are generally always male— of cybercrime. They might be recruited to act as gophers or mules for bigger players, who in turn could be connected to pedophile rings, mafia gangs, or even terrorist cells. Professor Andrew Blythe, an expert in cyber forensics at the University of South Wales, has been explaining to me how the hierarchy works, from individual script kiddies or new recruits to cybercrime’s own civil service.
Speaker G: State hackers have access to training. They’ll be recruited because of their skills. They meet at conferences like DEF CON, Black Hat, 44Con, where you get a lot of script kiddies going there, what we call the wannabes. I want to be a hacker and I’m going to go there and I want to try and learn some tricks and things like that. So they do meet and they do socialize. Things to remember: every hacker had to begin somewhere. Every hacker was a script kiddie. Every hacker started from no knowledge and worked up to the level of knowledge that they’ve got. So there is this process that you go through in becoming, let’s use the phrase, uber hacker, a good hacker. There’s a learning process that you go through. In terms of the supply chain, those people that break in and steal credit card details, they will then sell them to middlemen. The middlemen then sell them on to people that can make money for them. So what we’ve seen in the organized crime world is a quite sophisticated supply chain being built up of people breaking in, selling information to middlemen, middlemen acting as information brokers, and then selling that on to parties that can monetize it and make money out of it.
Speaker C: So what you’re saying then is that you’ve got people performing different roles. There’s somebody who builds a suite of software tools They don’t want to get their hands dirty, so they franchise them off. You know, there was something called Zeus, wasn’t there?
Speaker G: There was, yes. I mean, so you get malware written where people will write malware and sell it. You see botnets being rented out for spam email. So it is being monetized and people are providing services. So you can rent time on a botnet if you want to do some password hashing or breaking of passwords. If you want to do some spam email, You don’t go and do these things yourselves. You rent time on a botnet or something like that. If you want to have a piece of malware, you don’t necessarily go and write the malware yourself. You’ll go and buy it or rent it from somebody who’s already written it and is selling it on the black market.
Speaker C: So it’s very sophisticated. This is an industry, and it’s always as though, if you want to use an analogy, there’s a street on the internet and it’s Crime Street, and you just turn up and you buy X amount of DDoS time, and then you go into another person, and from those you buy X number of hacked credit cards.
Speaker G: It’s exactly that. But what you find as well is that some governments tolerate this because they use these individuals from time to time. So you tend to find that the black market has particularly thrived in countries like Russia, where we know that Russia has a philosophy of using cyber mercenaries to achieve political ends. One only has to look at the attack in Georgia to see where a cyber mercenary was used.
Speaker C: What you’re saying then is that this is, again, I mean, it’s an industry, it’s a different world, it’s a world where people are used, that you might get somebody who is one of these script kiddies being groomed, they might be being used by somebody who is very, very sinister.
Speaker G: Yes, and there have been reported cases. There was a case in America where an Israeli hacker was grooming two US hackers to do work for them. So we certainly see that going on. And it’s all about hackers that are doing nefarious things, trying to put barriers between law enforcement. This is why we see the use of complex VPNs. But we see complex networks being built up by criminals bouncing through multiple jurisdictions to make it difficult for law enforcement. So if I want to break into a computer in America, I might first break into a computer in Russia, I then might break into a computer in Brazil, and then I’ll attack the computer in America. And I’m going through multiple jurisdictions to make it hard for law enforcement.
Speaker C: There was a situation, wasn’t there, with the hacker Solo, the Scottish hacker who was based in London. He, it’s said, was actually recruited by other people, that he was on a portal or in a hacked portal that belonged to a telecommunications company and that people were actually using him.
Speaker G: Is that what you’re talking about? Yes. So people will use script kiddies. They’ll give them tools they’ve developed. The script kiddies do it because they want the knowledge, they want the skill, they want to be, hey, look at me, I broke into this. The people that are grooming them, they’re wanting to step back and hide behind them so that to make it difficult for law enforcement. And it could be that they’re being paid to do it. I mean industrial espionage has been with us for a very, very long time. There’s a saying in law enforcement is that while technology changes, the crimes don’t. So you know we still see extortion being done but instead of people throwing bricks through windows, what we see is people mounting denial of service attacks. We still see industrial espionage being done but instead of people having to be there with the James Bond microfilm photographing designs for top-secret planes. Now it’s done by the internet, sat in your lounge with a Wi-Fi connection and doing it for your home computer.
Speaker C: Professor Blythe mentioned denial of service, or DDoS, as one of the weapons in the hackers’ armories. This is what happens when a website is forced to crash. Israeli cyber expert Matthew Andriani is the CEO of MazeBolt, a company that specializes in trying to head off these attacks and mitigates their effects. He explains 3 different ways that they can be used.
Speaker H: DDoS is a problem because the more we rely on our services and infrastructure being up and running, the more it will affect everybody the moment that those services are unavailable. DDoS attacks, distributed denial of service, is an attack vector that is designed to disrupt services such as web, email, VoIP, similar to the conversation we’re having now. If there was a DDoS attack happening, it may be that we couldn’t talk to each other. So DDoS is a big problem. It’s been in the in the news a lot. Companies have suffered very, very bad attacks in 2018. I’m sure we’ll see the same in 2019. The average attack costs an enterprise— there was a very interesting report released by Noostar, a large DDoS provider in the States, that it cost on average, out of over 900 enterprises surveyed, that it cost on average $2.2 million $1,000 per DDoS attack that they suffered. 85% of those enterprises had a DDoS attack. So it’s a big problem and it’s not close to being solved.
Speaker C: And DDoS, just, just talk us through what a DDoS attack is because they’re changing, aren’t they? I mean, a DDoS attack was sending lots and lots of simultaneous messages to either an internet website or to an internet service and making it crash. But we’re seeing some very, very sophisticated use of DDoS now, aren’t we?
Speaker H: That’s right, Pete. We’re seeing in the past, you’re right, what started off what actually was called DoS, denial of service attack, where a single node used to send maybe old names, ping of death or teardrop style attacks they were called. They used to just send from a single host some type of a lot of traffic that used to take down on an internet site or someone’s server. Today, what you’re seeing is you’re seeing malicious threat actors creating what’s called a botnet, where they control a lot of computers all over the internet, computers, servers, computing nodes, let’s refer to them as computing nodes all over the internet, thousands or even tens of thousands they control. And what they do is they send from all of those nodes either very high volume of attack traffic, or they send a very high rate or very sophisticated packets that would go to a service and take that service down. And it may not be so obvious to see what took that service down. For instance, if I send from all those thousands of nodes very high traffic, it becomes kind of clear why I’m down. But what the attackers have done, when you talk about sophisticated DDoS attacks, is they’ve kind of integrated with what looks like legitimate traffic, but in fact is attack traffic. And those are very tough DDoS attacks to stop. Not that the others are not tough to stop, but those are particularly tough to stop.
Speaker C: And so what are criminals getting out of this though? Essentially, the way that you’re talking about it, it just sounds like a simple act of vandalism and just something that’s, well, more than annoying, is extremely frustrating.
Speaker H: Right, and extremely costly. That’s frustrating, costly, and very disruptive. So I think, I don’t think, I know that what we’re seeing, especially with the clientele we’re working with mainly in the enterprise space, so we see that a lot of the reasons that these enterprises businesses are attacked are either for— they get extorted, blackmailed. They get told, hey, either you’re going to pay us $30,000 or $50,000 worth of Bitcoins, or we’re going to DDoS you and take you down. So it’s a good revenue stream for attackers. And you can imagine if you are an eBay or an Alibaba or BBC or Fox News or anyone else that has to be online for their business to function, You don’t want to go down, and you’re going to pay $30,000 or $50,000 all of a sudden doesn’t look too bad to pay rather than go down for a few hours. That’s one reason. The other reason is maybe you as a company or on a national level as a government took a decision that’s not popular, and it’s what’s called hacktivism. They’ll start to attack you because they think that whatever you you did was so bad that they should attack you and take you down to teach you a lesson or to try to get you to change your ways. The other less common reason that people attack you is because they may want to use it as a smokescreen. For instance, unlike a traditional attack, let’s say a phishing attack, where it’s quite a quiet attack, you know, the attacker takes control of a machine or grabs credit credentials quietly by emailing somebody. When you’re under a DDoS attack, everybody is aware. Let’s take a news site, a popular news site. If they, if they’re under attack, all of their customers know that they’re down. Or stock exchange— if the stock exchange is down, everybody knows that the stock exchange is down. All of the stock exchange’s IT personnel are trying to deal with the attack. The attacker might be doing something else that’s malicious. They might knock out certain protections that normally work when— this is a less common attack vector, but when the, when the systems are functioning normally, their systems are not vulnerable. But maybe when they get hit by a particular type of DDoS attack, those systems open up in a way that they wouldn’t normally open up and allow the attackers to exploit certain vulnerabilities that they wouldn’t be able to exploit. For instance, if a web application the firewall was functioning correctly. So the summary is, is that it’s threefold. It’s for extortion and blackmail and ransom, and it’s for hacktivism, and it’s for trying a third type of attack on the organization.
Speaker C: We’ve been told about another sort of attack, which is, it’s almost like a death by a thousand cuts. So what actually happens is that a website’s response time is slowed. It’s not taking such an obvious attack from a DDoS attack, but it’s taking enough just to slow down its ability to be able to serve you up the pages that you want. And it’s based upon the fact that if we don’t actually see a web page downloading now within less than, well, around 5 to 7 seconds, we become frustrated and we can quite easily desert that website and go and find something that responds a little faster. And it has been suggested that some companies pay to wear down the response time of a competitor. Is that something that you’ve seen?
Speaker H: That’s also true. Yeah. Yeah. You got me. I forgot that point. That’s a very good point. In fact, we are dealing with a company now in the payment industry, payment card industry. Where they have been, they have now direct evidence of competitors paying threat actors to take them down, not slow them down, take them down. But slowing down would be just as good. You very accurately said that I think statistically anything more than 5 seconds, you’ve already got some kind of attrition rate and that would cause financial damage to a company. So for instance, if you you’ve got two payment card companies that are competing for some particular area, it may be in the competitor’s advantage to launch attacks against you. And we see that also particularly in the gaming industry. Gaming, I’m talking about like, you know, William Hill and all these big kind of gaming companies.
Speaker C: Sorry, Matthew, isn’t it a combination of the gaming, of betting industry and gaming industry?
Speaker H: Both of them. Yeah, both of them. You see that they, they are under a lot of DDoS attacks, and you can be sure that that’s because of the competitive nature of that, right?
Speaker C: Because obviously on the online gaming industry, if somebody’s launched an online game and it’s very important for people to have a very good response time— remember that some people have actually made an investment to get a very, very high speed link straight into a server so that they— straight into a server farm so that they can get a fast response time. If that is being mitigated by a DDoS attack, then obviously these people are going to get frustrated and the game will lose credibility. That’s correct.
Speaker H: And for instance, another good example is if you’re having a poker tournament and in the final round of the poker tournament everything goes down or in the last few hours of it, everything goes down, or during some kind of horse race or something like that. So yeah, the gaming industry is a big magnet for DDoS attacks. And we see that actually those industries can quantify exactly how much money they lose when they are down. They know that if they’re down for 1 hour, they know very quite accurately how many customers are leaving them. They’ve got the stats down, and that’s why you’ll also find that those industries have invested incredible amounts of money into anti-DDoS systems.
Speaker C: One problem with cybercrime is that it’s underreported. Companies that get hacked don’t want to publicize the fact since it damages the trust that their customers have in their brand. They are obliged by law to report data breaches and ransomware attacks to the cyber watchdog bodies known as CERTs—Computer Emergency Response Teams. And the Information Commissioner, but they would prefer to keep them as quiet as possible. Marriott does not yet know of the impact of its hack. Its business may take a massive hit. And individuals? Well, nobody wants to look stupid, do they? Russ Martin is leading a campaign by Barclays Bank to persuade customers who fall for scams that they should seek help right away and overcome their embarrassment.
Speaker E: When you’re online, you know, there are things that can protect you in terms of security software, but actually the weakest link in being caught out when we’re online is actually yourself, the human being. You’re the person who can control, or the only person who can control, some of the actions that you do in terms of opening those emails and then clicking on them. So we really need to think about What are we doing when we’re using technology? Are we up to speed with, you know, some of the key things that we need to be aware of? Because these scams are changing all the time. Once the fraudster, or we, have an understanding of what they’re doing, they’ll suddenly move on to something else and catch us out in other ways. So we all have to take the responsibility of keeping ourselves up to speed and not relying on somebody else to protect us, whether that’s technology or or the actual company organisation we’re dealing with. I think just from Barclays’ point of view, we’re very keen to help not just our customers but people in the local community. So this is probably the biggest marketing campaign that we’ve ever run in terms of educating people about how to stay safe online, and this isn’t something that we’re going to continue to do this to make sure that everybody does stay safe.
Speaker C: One of the things that the criminals do, I mean, to go back to psychology. The other thing that they play upon is that people don’t like being seen to be stupid. So when they actually get caught out, people are very reticent to actually say, ‘No, I lost £2,000 online.’ ‘No, I lost £5,000 online,’ because they don’t want people to think that they are stupid. And the criminals are exploiting that too, aren’t they? They are indeed.
Speaker E: One of the things that we’ve done at Barclays is to really encourage people to come forward when they are the victim of a fraud or scam. And you’re spot on that people are too embarrassed to step forward because for some of these people, they actually may work in jobs where they work with technology, they consider themselves to be tech savvy. And I guess for those people in particular, that’s where there is real embarrassment. But no one should be embarrassed. The, the tactics we discussed that these fraudsters and cyber criminals use are so sophisticated that Unfortunately, there will be people who will potentially get caught out, and they should step forward, and if they are a victim, contact their bank, because there’s so much that we can do to support people, both in the moment where we might actually stop them losing money, but also what we’re finding with fraud and scams is there’s a real emotional, not just a financial impact, but an emotional impact for people, and actually some of these people really do need the support at that moment. So we’re encouraging people to step forward, however much they may have lost, or they may have just been a— they might have been a very near victim in terms of what’s happened— is to come forward, and we can certainly offer support.
Speaker C: Actually, that’s a very good point, isn’t it? Because as well as thinking that you’re stupid, a lot of people do, as you say, they feel psychologically hurt in some way and they don’t have anybody to talk to about it. They’re actually sitting there and they’re feeling not just stupid, they’ve lost financially, and they’re feeling really hurt.
Speaker E: Yeah, there’s some very vulnerable people out there, and I guess this is the people who can actually be impacted the most. They may not have family around them, they may be of the older generation. So actually, I think one of the things we can all do is actually reach out to friends, family, people in our local community to make sure they are being supported, and I think we really have to have a proactive approach to this. We can’t be waiting to fall victim. We need to make sure that we are doing everything in our power to make sure that we are protecting ourselves. But think about those people around you who may not be getting the support they need, so reach out to those people and make sure that we can all protect people.
Speaker C: A good protection method is to have strong passwords. Change them frequently and never share them with friends or family. One good method is to use a method mentioned by Sherlock Holmes: open a book and take the first or last letters from the lines of a particular page, or do a similar technique with a favorite song or poem. Most of us are not good at this kind of digital hygiene. But if you want tips and advice, go to www.csri.info. We even get sucked into unwitting single password proliferation. Along comes a new app that invites us to sign in using Facebook, so we do. A cybersecurity expert, Jarno Niemela of F-Secure, warns: This federated authentication, as he calls it, carries more risks. Jarno says this was proved in the Quora hack when 100 million user details were stolen.
Speaker F: What I would recommend is that don’t use federated authentication for anything critical. And if you are using federated authentication or a service, you have to consider why that particular entity is providing the service. Kind of providing the federated authentication is not free, so why are they providing it? For example, I don’t know what are the Facebook’s limitations on the data they can use on the authentication, but technically they are totally aware what other services you are using. Anything after that. Are you really willing to tell that information to Facebook? So if you would be using a federated authentication, my recommendation is that use it mostly for services that are not critical for you and choose as neutral federated authentication provider as possible. So for example, if some services accepting Microsoft authentication, I would trust Microsoft’s integrity or Apple’s integrity that they are not using the information what service you are using on anything of their own purposes. While then somebody who is very well known that whoever is using their services is raw material to be refined and sold onwards rather than actual customer, well, I really wouldn’t be using that kind of a service as a federated authentication provider.
Speaker C: But yeah, I mean, all of this does, it does beg a question, doesn’t it? Everybody’s being told to use different passwords for different things, and if you are using this one password for everything then it is a significant weakness because, you know, let’s face it, most people are very lazy, aren’t they? So what they’ll do is they’ll say, yeah, I’m just going to use my Facebook account for everything. But then, as you say, you’re dependent on the people who are securing those details on these various other services.
Speaker F: So that’s why what I recommend is that spend a bit of effort on using— on creating unique passwords and using a password manager for that, and then let the browser remember. The browser credentials are not easy to access, and that means that your computer has to be personally taken over. So if you are going to be lazy, be lazy on equipment that you own rather than using a service provided by somebody else.
Speaker C: Which comes to the other question I wanted to ask: if you are using those Facebook or those Gmail or Google credentials to log into another service, does that mean that that other service also stores your Facebook credentials? Does that mean that they can see them?
Speaker F: They know then your Facebook cred— well, they’re not really storing your Facebook credentials as such, but they kind of know that you came from Facebook, and they most likely do get your Facebook user ID. I don’t—
Speaker E: I haven’t—
Speaker F: what, I haven’t checked exactly what data is coming there, but these services tend to be very chatty, so most likely there will be definitely some— well, there is some kind of a unique ID. Identifier. There has to be, otherwise it wouldn’t work. And most likely, if that unique identifier is not your Facebook user ID, there will be definitely a way of figuring out your Facebook user ID from that unique identifier. So it is a data leak in both directions. And then that means that you should use them for services that you don’t really mind that they know both ways. What’s happening. So Quora, I haven’t really used Quora myself, but I would imagine that that is one of these services that don’t really matter that much. So using Facebook for that probably is not the end of the world. But for many other things, yeah, there might be things that you don’t want to happen.
Speaker C: Essentially what you’re saying is, as you’ve said, these services are very chatty between each other. Whereas one of the things that Google prides itself on, or says that it prides itself on, is that it’s very good at cybersecurity. They can’t guarantee that if their services are being used to authenticate other services. That then becomes an inherent weakness.
Speaker F: Yeah, and the thing is that they are very good at cybersecurity, but I wouldn’t call Google a privacy company. I would, I would say that in many ways they are opposite of the privacy and they are very good at securing their services. So you always, when you are talking about cybersecurity, you have to ask against what, what has been taken into scope when they are dealing with security. And actually, when we are talking about this federated applications and everything else, one other very important thing is that for critical services you always need to use a unique password, but in addition of that, you always should use two-factor authentication whenever possible. So that even if somebody would be able to get your passwords from somewhere, he still would have to be able to bypass the two-factor authentication. And of course, if you are using password manager for the passwords, for example, All of my passwords are typically 32-character random strings. Good luck breaking that.
Speaker C: What you’re saying is two-factor authentication is really the solution, yeah?
Speaker F: It is about as good solution as we have been able to figure out right now. Of course, two-factor authentications also come with their risks. If you are using your phone number, or as a phone number, and as, for example, phone call or SMS authentication, then you are vulnerable for SIM swapping, which means that somebody may be able to fool a support person at your phone company to issue a SIM card or a second SIM card with your phone number and then impersonate you. And this has been especially in cases of identity thefts and identity thefts of stealing money from crypto banks and crypto exchanges. So that is one risk. But then if you are using a phone-based authentication software, which is of course far more secure, then you are in an interesting situation when that phone breaks without you being able to take control over that. For example, I was just about to install a bank two-factor authentication software for my son’s phone. And the phone broke. And now we would be in an interesting situation that my son wouldn’t be able to access any of his bank information because the phone that had the two-factor authentication component is broken.
Speaker C: So even two-factor authentication, in which you have to provide both a password and a phone number in order to receive a once-only code number, is not totally foolproof. I noticed that Jarno himself uses a password manager, and all his passwords are random strings of letters and numbers. You can buy password managers like Dashlane and Password Boss, and there are some free products too. Or you can buy a book like mine that lets you store encrypted versions of your passwords on paper in a form that only you understand. Its beauty is it’s not online. According to SplashData, the most common passwords used online in 2018 were the numbers— you’ve guessed it— 123456 and the word password. But there are some surprise new entries in the league table. Donald is one. Charlie, Princess, and the rather sinister 666666. Perhaps even more worrying, SplashData is able to compile this table because more than 5 million passwords have been leaked onto the internet. When it comes to radio shows called Password There is only one, and this is it. We’ve been taking a critical look at the technology industry for 5 years now on Resonance FM, and we’ll be back next month with another edition. The producer is Blue Buffery, Jane Wyatt wrote the script, and I’m Peter Warren, the author of Cyber Alert and Cybercrime and Warfare. Thanks for listening, and goodbye.
Speaker E: This program has been brought to you by Resonance 104.4 FM. If you liked what you heard and want to support our work, please make a donation at fundraiser.resonance.fm.
