Menu

  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
Podnion
No Result
View All Result
Subscribe
  • Login
Podnion
No Result
View All Result
PassW0rd – 10 September 2025 (What’s In A Name)

PassW0rd – 10 September 2025 (What’s In A Name)

Play

Speaker A: This program is brought to you by Resonance FM.

Speaker B: If you like what you hear, please support our work by making a donation at resonancefm.com/donate.

Speaker C: Hello and welcome to Password on Resonance FM with me, Peter Warren, the program that tells you how your technology works. And in this month’s program, What’s in a Name, we look into cybercrime and in particular cyberstalking. Cyberstalking is using technology to find information about people online. They can be people you know. Often they’re not. They might just be someone you’ve seen in the street, in an echo of the Kinks song about a young man and girl who catch the same train. But cyberstalking goes a lot further because with the advent of the mobile phone, you can take a picture of that person on that train, upload it to the internet, and then do an image search. It sounds just what it is— very creepy— because people do not realize exactly how easily they can be exposed by a simple scrap of data. And cyberstalking is alarmingly on the increase. According to research last July from University College London, cyberstalking is one of the fastest-growing modern trends, and its impact is not taken seriously. The researchers analyzed responses from 147,711 participants aged 16 to 59 across England and Wales and found that in the last 12 months, physical stalking had affected 1.3% of those people. Cyber-enabled physical stalking had affected 2.2% of those people., and cyberstalking had affected 1.5% of them. But cyberstalking was the only category to have increased significantly over time, showing a 70% increase in 2012-13 to 1.7% in 2019. While between 2012 and 2020 Physical stalking increased by only 15%, and cyber-enabled stalking— that’s stalking where you’re using cyber to actually help you physically stalk someone— had decreased, highlighting the shift from calls and text messages to more internet-focused stalking behaviors. The research also showed that public perception of cyberstalking did not necessarily correspond to its legal status. Half of people who’d been stalked in the last 12 months said their experience was wrong but not a crime, while only 26% identified it as a crime. Those who faced solely physical stalking were more likely to view their experience as a crime compared to those who experienced only cyberstalking. Much more interestingly, Cyberstalking was also more likely to be committed by individuals not known to the victim, with 32% of cyberstalking victims having a domestic relationship with the person who was stalking them, compared to 69% of cyber-enabled stalking victims. The findings come against the backdrop of figures from the Office of National Statistics, which reveal that 1 in 7 people aged 16 and over in England Wales have been a victim of stalking at least once, with women and younger people the most targeted. An estimated 1.5 million people aged 6 years and over experienced stalking in the year ending March 2024. Among women, 20.2% have experienced stalking since the age of 16, as have 9% of men. An OIS report on the figures highlighted the psychological trauma of stalking, with one victim saying, I’ve lost my life, my livelihood, friends and family. I’ve lost all trust in everyone and view everyone with suspicion. I cannot sleep as the nightmares follow. It’s a very modern phenomenon that has become much more common because of people’s increasing familiarity with technology, according to Len Noh, a confessed former criminal and Hells Angel turned good guy hacker, a job known as penetration testing. No, he’s also a transhumanist who has 11 different digital devices implanted in his body. As No says, the first thing that you should do is dox yourself. Search online to find all of the information you can about yourself.

Speaker B: One of the things that I did back when I did my presentation back in 2020 is synthetic identity. I doxxed myself. And the truth is, it’s a lot easier here in the United States than it is in the UK and in Europe, just because of the GDPR and the right to ask for the deletion of your records. But I started with just an email, my company email, and was able to get all the way back down to my personal phone number, my address, my past 4 previous addresses that I lived at. Then I, because I’m a public speaker and I’ve actually presented in 73 different countries on different cyber topics, I’ve presented in front of the European Union ministries, the CERT for the Baltics. There’s a lot of data out there on me. And when I compiled it all, I put it all into a custom LLM and I was able to actually ask it questions and it gave me I would say probably 80 to 85% correct answers about topics that were not necessarily discussed in those articles, just based off of what it was able to get from the doxxing, the pulling in of all the different interviews and all the background it was able— I was able to pull from Facebook, Instagram, things like that, shoved it all into one model, and it was actually able to answer based off of what it had been able to ingest with a very, very high degree of accuracy on topics that not even technical related, based off of what my technical responses were.

Speaker C: Were you— one of the points that some people have made to us, and they’ve made in other programs that we’ve recently made, is that the LLMs and some of the AIs can actually make up information. So presumably—

Speaker F: oh, absolutely.

Speaker C: It’s about you, so you can check it yourself. But If you were to do that on somebody else, I’m assuming that you would be able to also check that too.

Speaker B: To an extent, I’m in a unique situation when it comes to the LLMs because my background is actually the COVID of my book. So I released my first book last October and I found out in early December that my book, along with a couple other authors that I know in the tech space, all of our books were part of a torrent that was actually ingested by ChatGPT. So the funny thing was, once we realized this— I do also do a couple of podcasts. One of them is called The Cyber Cognition, and my partner is a gentleman by the name of Justin Hutchins, and he is the author of the book The Language of Deception. After both of our books were ingested, we went out just to see what would happen and said, write me a paragraph. And I know this is going to sound strange, but I live on a bird farm My wife is a bird farmer, so we have a lot of peacocks and guinea fowls and chickens and things like that. And I asked ChatGPT to write me a paragraph in the style of Len Noh about herding peacocks. And my background is a black hat. I was an active criminal for the majority of my life. I’m a former 1%er outlaw, kind of Hells Angel biker kind of person. I have very specific words that are very common in, in my dialogue, and it pulled out something that, as I was reading it, it was like, oh my goodness, this, this AI and this LLM has me down. And then we said the same thing about Justin, and Justin is a former military, he’s a retired military, very structured guy, and you could definitely see the influence of what it was able to get out of those books in terms of our writing style. And it was spot on. And honestly, it was one of the more screwed up feelings I’ve ever had. The only other time I felt like that is the first time I found a deepfake of myself. Somebody in France actually took a static picture of me and turned it into a motion video to try and sell software for a company that I wasn’t working for. And to your point, I don’t speak French. So when I found it, it was extremely unsettling. After the initial shock of, this is really bad tech, I— if you’re going to deepfake me, you know, put a little bit of effort into it. I looked like— you remember those old, you know, kids shows where it was just the standard picture and just the mouth moving and nothing matched up? That was me. I’m like, if you’re gonna deepfake me, at least put some effort into it. But I had to contact a French colleague and go, What are they even saying? It was very unsettling because to your point, you know, when we talk about LLMs, deepfakes, and things of that nature, if you don’t know me, this could have multiple rings of consequences, starting with my job, my reputation. God forbid they say something that could be considered off-putting or controversial. And The people that know me would know that I wouldn’t do that, but if you don’t, I’ve often questioned whether or not individual identity insurance is— may become something more than just for corporations or famous people. We have identity insurance when it comes to our identities from a financial perspective, but I honestly expect there to be something along the idea of identity insurance for social and potential deepfake scenarios coming out as a service here in the near future. This is— that’s just one of my predictions because I— the need is there. We have apps now that are designed specifically for those purposes, you know. And the honest answer to how easy is it to cyberstalk someone or try and— that if we’re going to talk about this, I would suggest that we use the, the correct term. And for your listeners, if they’re not familiar with this, the term is actually called OSINT, or O-S-I-N-T, which actually stands for open source information technology. And the truth is, depending on where you are geographically located will determine the ease of access. Here in, in the United States, information and the distribution and proliferation of information is a service, and it is a multi-million dollar business. We have companies out there— one that I use quite often in my day job as a pen tester is called BenVerified. And this is a service here in the US that if I put in someone’s name, someone’s address, someone’s phone number, this will basically do all of the data collection against every open source, uh, database available— property records, phone records, Department of Motor Vehicle records. Back in 2020, just to prove this point, I actually went out and decided I’m going to see how much information is out there on me. And I started with commercial tools. Like I said, I use BenVerified. There’s another one called Checker. Here in the US, you can throw a stone and hit a company that will provide you information. After I used the BenVerified, I went into open source tools. One of my favorite is called Spiderfoot. This is a Python program that will go out and literally spider the internet based on queries. So I used that. I used a tool called Blackbird and And I used a tool called IKY, which stands for I Know You. And between those 4 different utilities, I was able to basically make a digital copy of my digital persona. And once I decided to start leveraging AIs and LLMs against that, I was able to have conversations with my digital identity. I could ask it questions that, like I said, were not related to tech. I asked it questions related to philosophy. I asked it questions related to my past. And just through the correlations of knowing where I grew up, it was able to determine what elementary school I went to, what junior high school I went to. It was everything that I would never want to put out there to the, to the world. And I actually made— did an entire presentation and video this, and I showed it around the world, and everybody was asking, well, Glenn, why are you putting all of this information out there? Why are Why are you showing it to people? And the simple answer was because somebody else could go and do the exact same search that I did for $12 a month. So there was no point in trying to hide it.

Speaker C: So basically what you’re saying is that you could use a combination of apps, a little bit of AI, create a model of somebody, and then get a fairly representative reaction of or reflection of who they are and what they’re doing.

Speaker B: Absolutely. The only difference between the US and, you know, you being there in the United Kingdom, you actually have much greater data privacy laws than I do. You have the ability to request your medical records be deleted that, you know, any once you’re done with a service, they have a certain amount of times to delete all of your data. The one thing that I find really disturbing about the whole identity issue here, especially here in the US, is we have turned data into a recurring services business. And as such, being a capitalist society here, there’s no way that they’re going to ever let that go.

Speaker C: Ethical hacker and transhumanist Len Noh on how to stalk online and how easy it is to to do. During our research, we found that the lines between online stalking blur. Often, people are taking advantage of technology simply to find out things about other people. Once they do that, then it becomes a question of intent, because there is so much information about each of us online. You might simply be interested in someone, Or if you’re a criminal, you could be researching a company and looking for information on particular individuals. Paul Bishkov of the technology website Comparitech regularly investigates and writes about online privacy, cybersecurity, and the risks individuals face from seemingly harmless personal details. Here he explains the trend.

Speaker E: But, you know, you— let’s say you use your email address to sign up for a website. That’s the most basic online interaction. You give that website your email, that website can then take your email and give it to third parties. That can be marketers, that can be anything from a private detective service to the government to anything like that. It could be a hacker who goes in and steals that information. So through this information being stolen or shared or coerced out of this company in some way or another, simply giving up your email address allows all these other people to suddenly target you with emails. Plus they know your email address so they can use that email address to try and hack into your accounts if they find out your password. So, you know, it’s just that little simple interaction leads to, really increases what we call your attack surface and allows a lot of people to target you with various cyber attacks.

Speaker C: People have been talking about something called cyberstalking. What is cyberstalking?

Speaker E: Cyberstalking is similar to real-life stalking where, you know, you’re, you’re basically haunting someone’s footsteps online. You’re trying to follow them around, see where they post, what websites they use, what apps they use, finding what information they have online and using that to divulge other information about them. For example, if you can find out someone’s IP address, which is, you know, a number that identifies their device on the internet, you can use that to find out their approximate location. So things like that, you can use all these bits, hints of information that people give out online to find real-world information about them and stalk them.

Speaker C: If you wanted to do that, how much information could you get on somebody? You say this IP address, you— what you basically seem to have just said is that with that I could even find out exactly where you were. I could find out your geographical location if I know where your device is.

Speaker E: Yeah, with an IP address, you could learn that. And so it depends on, you know, is this a person you already know in real life or that you’ve met somewhere, or is this a complete stranger? You know, that will determine how much information you can learn about them or how easy it is to determine information about them, because you can corroborate. If you know this person in real life and you can see them, you can corroborate information that you find online to make sure it matches up. That you’re talking about the right person. But if it’s a total stranger, you don’t need much to get started. There’s a whole industry, or there’s a whole practice called OSINT, or open source intelligence, where people use very simple pieces of information that people enter or share online to find out a lot more information about that person and dig up. They can find, you know, your, of course, your name, location, but also your age, your race, your marital status, your sexual orientation. Any of these things can be divulged from your internet history, your activities, and the other— and the information that you voluntarily give up online.

Speaker C: So there are actually people who are actively involved in doing this? There are people, there are communities on what, the dark web, or are they, are they a little more transparent than that?

Speaker E: They run the gamut. So there’s, uh, there’s open-source intelligence communities that are completely open on Reddit and other forums like that. People will go in and who need help saying, I need to identify this person from this old picture, or I need to find out where this photo was taken, and they’ll post the photo online and people who know how to do this work will help them. And so it’s not always malicious, but oftentimes it can be used maliciously. The most famous example, the most The most obvious example is doxxing. Doxxing is whenever you find a person and you, you go into their— you use the internet to find everything you know about them and then divulge all that information and dump it online so that anybody else can easily find out where this person lives, when they’re home, where they work, what, you know, all their internet handles and usernames are and things like that.

Speaker C: Okay, and I suppose this is the community then that worked so fast to identify the luckless CEO of Astronomer who was caught out in the Coldplay incident, who was identified within hours.

Speaker E: Yeah, you could use— I don’t know if it was this particular, particular community that I mentioned, but OSINT, open source intelligence, can be used for that purpose to find, to find out who that person, the CEO of that company, and find out who he was very quickly.

Speaker C: Yeah. So presumably then there must be a lot of activity that goes into stalking celebrities in this as well. I mean, you know, the press, people like me who were caught up in the phone hacking thing, presumably they could use this technology to actually discover a lot of information on other people.

Speaker E: Yeah, of course. And especially, I mean, if you’re a public figure, then it’s even easier to find you and find out that information. There’s going to be a lot more eyes on you. So the sort of threat is much bigger. We talked about threat models, individual threat models before. Celebrities have a much more porous threat model than most of us average people do.

Speaker C: When you say porous, how do you mean?

Speaker E: For example, face recognition. If somebody takes a photo of me and tries to figure out who I am based on that photo, they might get it right, but there’s a good chance they could get it wrong, and they couldn’t get it right with any— with a lot of certainty. But a famous person whose photo is everywhere, super easy to identify them right off the bat.

Speaker C: And what other information could you then get from there? Could you use that to home in on their internet history and do what you’ve discussed about going in and finding IP addresses, that sort of information?

Speaker E: Well, you have to just think about first, um, who’s asking that question. Are we talking about a corporation who’s trying to learn about you, a government, or just like an average citizen? An average citizen is going to have fewer opportunities to use this information to, to learn about you than, say, a corporation or a government or a law enforcement agency. As someone who’s also doing— following all the rules and doing it legally is going to be diff— be able to get different information than somebody who’s searching through stolen databases and dark web stuff like that. So first of all, you have to figure out who’s looking. But say someone found your face and identified you online, they can then go and find where that same— where your photo was taken in other places. So, you know, for example, you know, of course the Jeffrey Epstein thing is famous right now, but somebody could go use facial recognition to find a famous person’s face in every photo that Jeffrey Epstein has ever taken.. So we know now that that person has been photographed at all these places, and AI makes that process a lot quicker and more easy.

Speaker C: Paul Bischkopf, consumer privacy advocate at the online technology website Comparitech, pointing out that our email addresses and names are our online Achilles heel, the key to our identities, and in so many different ways, the access point to our lives for criminals, according to the entrepreneur Claudio Cogalniu. Who became so frustrated with the torrent of messages being sent to him that he developed Centria, a technology to filter them out.

Speaker G: So I’m from an email. You can’t really do much with it besides just spamming people. But when you, when you register for something, you don’t give them only your email. Usually give them at least your first name or even full name. And these two, if I were to describe what happens— so let’s say you register for, I don’t know, let’s say an e-commerce shop, and you register using just your first name and email just for browsing, you haven’t shopped anything. So, and let’s say a month or two later that company goes bust, and before they do that, they just sell your information or the user’s information to others to at least make up some loss. The new company, or whoever buys it, might be a legitimate company, might be actually a scammer. That can buy it, because this— all this information is quite cheap, and you can buy someone’s personal data like full name, email, maybe even a phone number for a few pence. Once it gets in their hands, knowing your contact information and knowing that you’re likely to purchase something in this industry, I don’t know, let’s say clothing or something, they know a bit more about you. If they sell this information further to another, like a phone company, or if that company buys your information from a phone company for, from some other thing, other interest of yours, now they have even more information about you. And the same goes for scammers and for hackers. When they get their hands on your information and knowing where it comes from, it’s a lot easier for you— for them to send you personalized phishing emails that are a lot harder to spot because they know something more about you that you wouldn’t expect a scammer to know. And from there, yep, you can send someone a scam, I don’t know, with some adventures in the woods or in the mountains, something like this. And from that attack, you can gather even more information about them or take control or make some money off of them, promising some, like I said, some adventure, because you knew that they might be interested in something similar. And yeah, that’s— this is a vicious cycle because I gave examples with 2 or 3 companies doing this. But if you imagine that there are tens of thousands of businesses that do this, it’s— in 2 days you just lost control over your personal information. It’s that easy. Yeah, that’s another reason why I started this, because besides being curious why— or actually, when I started working in this industry, I learned why I kept getting those scam emails, because this cycle of data selling kept happening years before the GDPR came into place. And the reason behind the business is both prevention and protection against these types of attacks. Like I said, many of us just register randomly for a lot of useless stuff, and our information remains there. But, and oftentimes if you register today for something that you were just curious in the moment, in a week you just forgot that you gave them your information. So this way, with, uh, the platform I built, it’s a lot easier for you to keep track of where your information is so you can take it off those websites as well as data brokers. So yeah, it’s this part is for the prevention and the scam emails. That’s the protection side. So it covers both bases.

Speaker C: Did you ever do an exercise where you tried to find out how much information could be collected on you and how that could be interpreted?

Speaker E: Yeah.

Speaker G: I actually did my Thinkium one in 2020. I kept sending data requests to companies I was registered with, and it was quite interesting. I sent one, I remember this, and I don’t, I don’t think I’m gonna forget it anytime soon. I registered for a fitness app. And when I registered, you just gave— I just gave all the relevant information back then, like my name, age, height, weight, and so on, and fitness level. And from this, only from this information, they could— they sent me back all the derived data that they came up with. Based on what I initially gave them, like what I might be interested in eating, or protein intake, or exercises, fitness equipment, bicycles, and so on. There’s, there’s a lot of that information. And for e-commerce, the main one is that they create like a value profile of you, how much value you have in their eyes, and if they care enough to keep you or let you go shop anywhere else.

Speaker C: Claudio Caccaonicianu, founder of the email protection system Centria. As Bischkopf and Kakao Nuchanu have pointed out, your email might be the way into many people’s lives, but once you’ve gleaned that all-important name, then information can just begin to flood out about a person, and profiling them becomes child’s play due to social media and recent developments in AI search. You might think that your device is the interface into the digital world, but you don’t know who’s watching you from their computer or phone. As Christopher Hawke, consumer privacy advocate at Pixel Privacy, explains, the internet never forgets, and often it can hold information on you that you thought had been committed to the mists of time.

Speaker D: They can use things like the Wayback Machine or the Internet Archive to track your previous online activities. I mean, they can go back for several years, especially early on in the early years of the internet, what, late ’90s and on into the 2000s. People didn’t think about security. So they were out there just dealing out their information. They were— they didn’t care. They’d put their real address out there, the real phone number. Here’s where I work. Everybody wanted to be seen, so nobody really took— or very few individuals really took the time to keep their tracks covered or to consider what they were leaving out there. So yeah, they can go back 20, 25 years, back to the start of the internet, and track and see what you’ve done out there. That’s it. Nothing ever gets erased from the internet.

Speaker C: Okay, so if for instance I wanted to get information about a particular target, say I’m a hacker and I want to find a particular individual who works within a company, I can do that. Can I find out what they’re interested in? Can I, can I get other details about them?

Speaker D: You don’t need really any hacking skills for that. All you do is find their Facebook account. Their Twitter account, their BlueSky, their LinkedIn. LinkedIn, I mean, that’s the source right there for all your government information. And you would just be amazed at what people do leave on their accounts or post on their accounts. It’s really, you know, only in the past, I’d say 10 years or so, people really started considering, wait, what am I putting out there?

Speaker C: Do you really think so? I mean, in With Facebook, people seem to blindly put out huge amounts of information. They put out information on who their friends are. They put out information on what they’re doing, when they’re at home, what their particular interests are. I mean, they don’t seem to really consider the privacy implications of that.

Speaker D: Right. They don’t think about it. And what scares me is a lot of people post so much information about their children, the photos, where they go to school, what their hobbies are. It’s just, I understand wanting to share, but there are private ways to share with friends and family. If you can make, you can make a post private, you can restrict who sees what. And I suggest that strongly for anyone, especially when they’re posting information about their children. Or their activities. Heck, some people even like, oh, I’m going to be on vacation for the next 2 weeks, and, you know, and they’ve already posted their address, you know, 3 years ago. And so, hey, there’s a nice place to go hit while they’re gone. Let’s see what we can find at their house. People really need to be more careful. Always think before you post anything. The first step is not going to be immediately to look for you specifically. They’re going to do a data breach, they’re going to get all this information, they’re going to start looking. Oh look, let’s check him out. Oh look, he has, you know, this job doing this and he’s probably pretty well off. Let’s see if we can scam a little off of him. Or they just cast a wide net with most, most scammy emails or texts are done thousands, if not hundreds of thousands at a time. They just go out to a big group of people, a big mailing list that they’ve gleaned from these data breaches. So just because you’re not the specific target doesn’t mean they won’t use that information against you or try to scam you at a later date.

Speaker C: And that’s the really interesting thing, isn’t it? Because it’s how information is used. Because one of the things that increasingly people are going to do is say to an AI, map out that organization for me, find this person who is a particular gatekeeper. What information have we got on that particular person? When people are talking about AI being used in hacking, well, this is how it’s going to be used, isn’t it? It’s going to be used to get that available information to identify the vulnerability. It’s not necessarily turning an AI system into some sophisticated software tool.

Speaker D: They could just use it basically as a really fancy shovel to dig for more information. AI can do everything from creating videos to photos to, uh, tracking down a CEO who got caught with his girlfriend at a concert. And even before AI, the internet was always really good at finding out who was in a photo. Photo. I mean, before AI, there were plenty of times that CEOs or well-known celebrities got caught doing something they weren’t supposed to. Or even just your average person— say someone cuts in front of you and flips you off. If you take a video and you put it on the internet, somebody would find that person. It’s their hobby. I don’t know. The people— the internet loves to track down people. People, be it with AI or just normal people. I think you can still have privacy, but it’s not going to be as easy as it was. The only way you can have privacy now, really true privacy, is to go find a shack up in the mountains. Doesn’t have any internet connection, doesn’t have any electrical or anything to connect you to the real world. That’s the only way you can have true privacy nowadays. But you can take steps such as using a VPN to hide your tracks and hide your activities on the internet. Use private email addresses or temporary email addresses. You can even go so far as to use temporary phone numbers. They’re disposable nowadays. You don’t even need to go as far as to go and buy a burner at the drugstore. You can just use a Google phone number. And it’s so if you don’t take the steps to protect yourself online or protect your privacy in the real world, you’re going to— people are going to have information. There’s no way to— I don’t think there’s a way to keep it as private as it used to be, but there’s still ways to at least control the amount of information that’s out there.

Speaker C: It’s interesting, isn’t it? Because apparently Facebook generate ghost accounts to explain the interactions between particular people so that they can actually understand that data. They can define the existence of somebody because they’re not there, because they’re missing in terms of a relationship. So what you’re saying is, yeah, that you can’t clean yourself out completely, but you can obscure, you can become a ghost.

Speaker D: There are going to be so many kids in their late teens, early 20s, that 10, 20 years from now they’re going to be applying for a job, and HR, before they get an interview, they’re going to check out and see what they did online. Let’s see, you know, what their beliefs are. Let’s see what what they’ve done online. Let’s see how they treat other users. And, uh, it’s just gonna— it’s gonna be a wake-up call in 10 or 20 years. It’s starting now. I see people online complain about, well, I didn’t get the job because they found something I posted 10 years ago. And I mean, it happens to politicians all the time. It’s almost too late, but there’s, there’s still time to keep yourself protected online. And I would suggest going back in your own posts over the last— check, get on Twitter. You can see your posts from years ago. Even if it’s even slightly iffy, get rid of it.

Speaker C: Christopher Hawke, the consumer privacy advocate for Pixel Privacy, on why you should really start to take an interest in who you are online and how you’re being tracked. You come across and whether you even want to be there in the first place. A decision that you should consider very carefully because the internet is like a coral reef, home to millions of pairs of eyes who might suddenly focus in on you for a particular reason. And it’s not just the criminals and stalkers who are watching you. As Peter Connolly, a former British Army officer leading operation in some of the world’s most volatile regions and the founder of Toro Solutions illustrates. Connolly, who has a background in military intelligence, counter-terrorism, and advanced risk management across both public and private sectors, has taken that experience and developed it into pioneering work in cyber-physical security. Essentially, you could call him a mind reader.

Speaker E: In cyberspace.

Speaker H: We’ve got a team of, of investigators and open-source intelligence experts that spend a lot of time trawling the clear, deep dark web for data. And we do that for ethical purposes. So we do it to take a look at our clients and their digital footprints and then advise them on how they can improve their security and privacy online. We do it for things like due diligence investigations. So before you work with a partner company, you might want to do some background checks on them. We even do it to enhance pre-employment screening and vetting. So before you employ somebody, you might want to do some background checks on them, particularly if you may end up sending them their new laptop to North Korea, which is pretty common at the moment. And we also look at threat intelligence to the businesses that we support as well. So we’ve got a, you know, 10-year track record of doing this type of stuff. And but the underlying point is we’re doing it for ethical purposes to basically help people and businesses stay safe. And the reality is most of the information needed to conduct a cyber or physical attack against an individual, their family, or their business is available on the internet. And some of it will have been put out there by the victim, and some of it will have been lost by online companies that have been breached, or some people will have just, you know, partners of theirs may have, may have released that information as well. So now that’s the first stage, I would say, in most attacks against an organization is open source reconnaissance, effectively. And the, you know, the information needed to conduct an attack against you or to steal your identity to commit identity fraud, theft, typically it’s anything that’s associated with your memorable information. It’s a start point like an email address, a social media account, phone number, a home address, a company you work for, your social network. So, you know, who it is you interact with.

Speaker A: It’ll be—

Speaker H: it could be the accounts that you use, so accounts you’ve got set up. And really, that’s where an attacker would start. And the information they can glean from, say, breach data is huge. You know, if you think about when you sign up for an online service, whether it’s an e-commerce site or whether it’s a dating app, you give away a lot of personal information, you know, potentially your home address, your phone number, email address, maybe banking information. And if that organisation gets breached, at best you’ll get an email saying, sorry, your data has been lost. But it doesn’t really help you as an individual now that that data is available on the dark web and may end up in the public domain as well. So, you know, when we conduct online investigations for our clients, you know, we find things like documents that have been posted. It could be a CV, it could be a pitch deck, but, you know, embedded in those documents is metadata that could be quite useful. Like, how many times have you received a PDF or a Word doc and just out of curiosity, you go and look at the document properties and you see someone’s name, or you see a different company actually created that document and then it’s been repurposed by the person that sent it to you. Sometimes in photos, it might be that that photo has been stamped with the GPS coordinates of where it was taken. Now, a lot of platforms scrape that metadata so it’s not visible to the recipient, but still, if you If you turn on GPS settings on your camera and take a photo and send it to me by SMS, I’m going to see where you took that photo. Other information— facial recognition is getting pretty advanced, so again, identifying the other people in the photos that you take. Often it’s possible, particularly when we do things like litigation support, so fraud investigations into individuals, we can we can find the location of where they are by looking at the background buildings, trying to triangulate those, even looking at things like shadows, plug sockets, you know, and sometimes you hear in video footage things like sirens in the background that can help pinpoint the country that they’re in. There’s a lot of information there which could narrow a search. It won’t— potentially won’t give you the coordinates of where that person is, but it will certainly narrow the search so you can focus other resources on finding that person. We’ve seen a big increase in online images, profile images that have been AI-generated for the purposes of fraud, and there’s some technology out there that helps you identify indicators that, that an image may have been tampered with.

Speaker C: Peter Connolly, the founder of Toro Solutions, on how to be more streetwise on what used to be called the information superhighway. It’s a process that Crick Gunning, the CEO of the identity verification company Fourth Line, which also works to screen out fake identities, is optimistic about. According to Gunning, we may have not quite realized the dangers of online technology and AI, but we can use the technology to try to correct some of the problems that it is causing for us and try to protect ourselves online.

Speaker A: Well, I mean, I think if we accept the fact that people have historically been oversharing information, You know that there is too much information with too many different organizations stored. And unfortunately, whether it’s large organizations or very small organizations, we know that not all of them are taking appropriate measures to protect that information, which means that there is information out there on each and every one of us. And I would look at the the problem in two ways. One is how can you basically stop the bleeding? So how can you prevent the oversharing of information going forward? That’s what we just discussed. And then the second element, how can you prevent the abuse of information that’s already out there? And that comes back to your very first question, which is how little information do you need to identify someone? And there my response was it depends on the use case, and I still think that’s true. So even if you are able to find every piece of information that’s stored of me digitally, that still shouldn’t allow you to do vital things like access my health records, access my bank account, access my tax returns, which means that depending on the use case, and maybe you will gain access to my social media account, and maybe it’s my responsibility to protect that, but I think the really crucial ones, There, there’s a responsibility on the gatekeepers to make sure that even if you harvest all of that information, you cannot get access to those services and those companies. And I think that is something you can very easily do with the technology that’s available, for example, with what is called server-side biometrics. So a lot of companies today rely on Face ID on a smartphone, which in the end is a signal where Apple, in my case, because I have an iPhone, will tell you that someone has successfully passed Face ID on that iPhone. There’s no proof actually of who did that. And we’ve seen recently that there’s many ways that you can abuse that if a bad actor wants to get access. So I think in these use cases, the onus is on these organizations to have what is called server-side biometrics. So they actually need to know what Peter Warren looks like and they need to make sure that if someone is trying to get access to these very, very sensitive services or the very, very sensitive data of Peter, that they establish in a proper way it’s really Peter. You can do that on a wide range of data points including biometrics which are on the organization side of the server, but then looking at them in conjunction with a lot of other data points where they can really verify whether it’s Peter and not someone trying to pretend they’re Peter. I think we have to realize that this AI technology can also be leveraged in a positive way where you can do vulnerability scanning in an automated fashion so that an organization actually knows where their vulnerabilities are and can fix it and can fix it much faster than we could in the past. So I think, again, I don’t, I don’t want to argue with you about the risk, but I do want to say that let’s not forget that that same technology is very powerful also on the defensive side.

Speaker C: Gunning, the CEO of the identity company Fourth Line, predicting that the technology that is causing such issues will eventually come to our rescue. Whether it will or not, we will wait and see. But in the meantime, Bill Mew, Future Intelligence and Tech TV’s very own privacy advocate, who along with Max Schrems and Viktor Mayer-Schonberg successfully argued who has argued for the right to be forgotten and along with Schrems successfully forced privacy rules upon Facebook following a €1.3 billion fine from the European Union, has a few practical suggestions.

Speaker F: Essentially everything to do with technology is about data, and in particular we’re talking here about your identity, and that means all the data that is pertinent to you. It can be anything from your name to your date of birth to your email to a whole lot of information that is peculiar to you through the fact that it’s your face or your DNA or your fingerprints. These are what are called biometric indicators. You need to be really precious about these and not share this information liberally without thought. But obviously you can’t be completely isolated. You need to share some information with your doctor for your health record, with HMRC for your tax record, and there’s a whole lot of people who will have data on you. But you just need to be a bit precious about who else you share it with, because actually once it’s been shared and gone to data brokers and beyond them to potentially to criminals, reclaiming your data and reclaiming your identity and your privacy is going to be very, very difficult. Some of the steps that you can take, and there’s some very sensible obvious ones. Firstly, just be cautious about where and when and what data do you share. Secondly, One of the top things that they’re going to be after is your email address, because that opens a number of different doorways. And therefore, if you’re going to use your email address, especially for logins and other things, make sure that you have multi-factor authentication. It’s not going to be the, the golden solution to all of your problems, but actually it will mean that you’re no longer the low-hanging fruit that the criminals are going to go after. They’re always going to go after the easiest target. And if you’ve implemented multi-factor authentication, it’ll just make you slightly more difficult to hack or to rob than anyone else. Finally, you can actually take some steps about being, in terms of cautious, about not sharing in particular your biometric data. One of the advantages with a lot of other things is you can reset your passwords, you can change a lot of other things, but biometric data you have for life. It’s your, it’s your face, it’s your DNA, and it’s your fingerprint. If somebody’s asking you for these biometric data, you need to ask them why, because they may be an organization you trust, but if they’re ever hacked or if they’re ever careless with your information and your biometric data gets into the wrong hands, it simply cannot be reset. The other thing is you can be aware of what’s out there, and there are some various different companies out there that will help with your privacy by going out to all the data brokers. Brokers and asking for your information to be removed. And that can be a very sensible exercise to do that would reduce the fingerprint that you have online across the internet. The issue here, though, is that these companies are only going to go to the reputable legal data brokers. They’re not going to go to the criminals who probably also got copies of your data, and they’re not going to be able to ask these criminals for the information to come back. In fact, that’s probably going to highlight you as somebody something potentially of value. And therefore you need to be realistic, first of all, about how you share data and what you share. Be particularly protective about biometric indicators. And if you go through the exercise of trying to pull down data, get it removed from data brokers, be realistic about the extent to which that is really going to make a difference, because the criminals aren’t going to comply.

Speaker C: And I suppose you should also In a sense, do a search for yourself. Look back on things like the Wayback Machine so that you can find information that you may have inadvertently, or things that you may have inadvertently said that you might perhaps have wanted to unsay. I understand that Nigel Farage has said that there are things that even he wants to unsay. And as well as that, You should also look at what you’re putting out on social media and perhaps weed that.

Speaker F: Well, obviously it’s this again. It’s down to the information that you share, and if you’re oversharing, then there’s going to be a lot more information available to you. One of the problems with social media is you may think that a lot of the information that you share is relatively innocuous, but it allows companies, not only Facebook and others, but there are more nefarious actors out there to build a profile on you. On you, what your sexual or political orientation are, other information, so they can profile you. And when they start profiling you, if they sort of profile data gets into the wrong hands, especially if they manage to get hold of biometric information on you, they can create everything from a fake video version of you to, uh, with an authentic sounding voice. And all these fakes can be incredibly realistic. And if they’ve also got your biometric indicators regulators that are the ultimate level of proof, then how is anyone to know that it’s not you when it comes to identity theft? Also, with regard to what you have online, there may be things that you possibly posted as a young person or a student that you might regret in later, later life when it comes to actually applying for a job or something. So you do have the right to be forgotten. So you can go back and apply to places and ask ask them to take down information, although again, it’s only the reputable people who are ever going to remove information of that kind. So you need to be careful of who you share it with in the first place.

Speaker C: Future Intelligence and Tech TV’s Bill New on some of the steps you should take to protect yourself online, because it’s a serious business. As Peter Connolly pointed out to us, in some parts of Europe. Cybercriminals use social media to identify children as kidnap targets, while websites like 192.com can yield valuable information to stalkers on where you live. As Connolly says, every hack on a big company adds to the wealth of information on emails, addresses, and passwords that is available to us in our online world, because In the future, with AI technology, incredibly convincing copies of people that we know can be made that will swim up from the coral reef of the internet and try to deceive us. According to Connolly, they’ve seen a big increase in the use of social engineering by attackers in digitally manipulating humans, a trend reminiscent of the mantra coined by the hacking group Anonymous Anonymous. First we hack the human and then we hack the device. For as Connolly points out, 85% of data breaches involve some human elements. So as you can see, on the internet you can be so much more than the name, and you should make sure that your good name is protected. You’ve been listening to Password on Resonance FM. Produced by the wonderful Blue Buffery and presented and written by me, Peter Warren. Thanks for listening and goodbye.

Speaker B: This program has been brought to you by Resonance FM. If you like what you heard, please support our work by making a donation at resonancefm.com/donate.

ShareTweet
podnion.com

© Sociaall Inc.

Navigate Site

  • Home
  • Privacy Policy
  • Contact Us

Follow Us

No Result
View All Result
  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
  • Privacy Policy
  • Contact Us

© Sociaall Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00