Menu

  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
Podnion
No Result
View All Result
Subscribe
  • Login
Podnion
No Result
View All Result
PassW0rd – 23 October 2025 (Securing the Metaverse)

PassW0rd – 23 October 2025 (Securing the Metaverse)

Play

Speaker A: This program is brought to you by Resonance FM. If you like what you hear, please support our work by making a donation at resonancefm.com/donate.

Speaker B: Hello and welcome to Password on Resonance FM with me, Peter Warren. And in this month’s program, we return to an old favorite. Cybersecurity, the cop drama of the technology world, and with good reason, because not only is this Cybersecurity Awareness Month, but it’s also a time when, according to our interviewees, we are facing a crime wave, an existential threat to our high-tech world, and in a shocking new development, threats of actual physical harm from the cyber gangsters. All at a time of blissful unawareness among our politicians, the population at large, and much of business. This is time to wake up. And in this program, in a first for us, we are making a combined radio and TV password for Future Intelligence’s sister organization, Tech TV. You can find out more about both www.futureintelligence.co.uk and www.techtv.live. Now, getting back to cybercrime. The situation is so worrying, according to some of those that we spoke to, that they are warning of a potential crime tsunami that will make the recent attacks on the UK high street that hit the luxury London shop Harrods cost the Co-op £120 million and crippled Marks Spencer’s computers and cost the company £300 million? Quite a cybercriminal’s picnic. Forget the last few months’ attacks that crashed Jaguar Land Rover and cost it £50 million a week and forced the government to consider a £1.5 billion bailout for the car manufacturer. Forget the attack on Collins Aerospace that left planes grounded across Europe. An attack using AI will soon be unleashed that will sweep up small and medium-sized businesses into the same sort of fatal disaster that saw the 158-year-old haulage company Knights of Old involved in a ransomware attack that jammed the company’s computers and put 730 people out of a job when the company ground to a halt. Here’s Brian Cute. Interim CEO and Director of Capacity and Resilience for the Global Cyber Alliance. That’s an international organization who works with the police, intelligence agencies, and internet backbone companies to improve the internet and help people and organizations to boost online security.

Speaker C: In about 2 years’ time, it’s estimated they will not only be using the warehouses of humans that they’re using to generate online scams. But by then they will have developed fully agentic AI, agentic systems that will be delivering a greater magnitude of scams and phishing attacks, more sophisticated than we’re seeing today in terms of video and voice, at a much greater magnitude 24/7, 365. And when you think about that, it means that there is a tsunami coming our way in the next couple years that none of us are prepared for. And there’s hundreds of millions of small businesses that are literally sitting ducks, and it’s on us to get them protected. To find a way to do that at scale, to get them the tools they need to make this easy to access, digestible, and the steps they take simple so they can be protected. It’s going to get a lot worse, Peter, before it gets better.

Speaker B: It’s a scenario that Cuke blames on the infamous Asian gangs on the Thai and Myanmar borders that have been heavily involved in people trafficking, cyber extortion, and online finance and romance scams known as pig butchering. Heartless confidence tricks that earlier this month saw a woman in England defrauded of half a million pounds by a man claiming to be the actor Jason Momoa. In her case, the thief stripped her of cash over a number of years, encouraging her to take out loans and to sell her house. She’s now homeless. As well as their criminal activities, the gangs are also involved in regional instability, funding the activities of warlords on the Thai-Myanmar border to staff their high-level compounds. The gangs entrap workers with the offer of jobs and then confiscate their passports on arrival, often torturing them and beating them to force them to work. The World Cup says that businesses across the world must wake up to.

Speaker C: How do we get the average person to feel comfortable approaching it? Well, for small business, we’ve observed the same thing that your other interviewees have been observing, which is they don’t prioritize it, they don’t pay attention to it. And frankly, a lot of them are small businesses just trying to make business and grow and serve their community. So understandable, but it doesn’t have to be daunting. It doesn’t have to be complex. I think the responsibility is on us, those of us in the cyber defense or defender community, on government and schools to try to raise awareness in a way that is engaging and that gets small businesses to understand this is a business risk we’re talking about, right? If your supplier went away tomorrow, you know, and your operations get shut down, that’s a business risk to you. Well, getting hacked, a ransomware attack that encrypts your data and paralyzes your business is a business risk. In fact, it’s one that can put you out of business. So, getting people’s attention in a way that translates, and then what’s important next is how do you present what they need to know? We need to make it approachable. We need to make it engaging, and we need to keep it simple. And that’s the only way we have a hope of getting folks to lean into this.

Speaker B: And that’s going to be the real problem, isn’t it? It seems as though we’ve all embarked on this technology journey and yet so much stuff is falling through the cracks. There’s almost this completely and utterly unprotected group of people out there In an environment that, I mean, some people have likened it to the Wild West. Strikes me that it’s more like the Barbary pirates, where you’ve got these ships going out, sort of raiding, taking people slaves, and then going back to these safe harbors. And they’re essentially demanding ransoms for people, from people to go into the, well, the internet’s the modern equivalent of the Mediterranean. That’s where we are. Do we need law enforcement to be rolling out and going to every single business and saying, hey, you should have this set of tools, you’ve got to be aware of what the risks are? What do we do?

Speaker C: Well, it’s going to require a concerted and collective effort, period. The internet is borderless. We’ve all seen that dynamic play out. It is, you know, I mean, nation states can have their own laws and regulations and implement them and enforce them. And that’s still a fact. But the internet in terms of the exchange of data and what the Barbary pirates can do is borderless. It’s going to take collective action. It’s going to take government. It’s going to take industry. It’s going to take not-for-profits, nonprofits working together, sharing information, coordinating in ways that allow us to take action. And that’s also very challenging terrain, right? I mean, you do have different legal regimes in different places. You have different requirements around data access and data sharing. And it’s quite a complicated landscape. And the clever cyber criminals, and now some nation states and more effective gangs, know how to exploit the infrastructure. So things like routing security, do people know that you could literally reroute traffic from an entire network to someplace it’s not supposed to go? Do people know that you could effectively take a country’s traffic down, that you can steal their personal data through that? No, most folks don’t know, but it’s a real problem and it’s one we’re trying to address. On the people side, on the end user side, whether it’s a small business or a not-for-profit or you or me.

Speaker B: Brian Cute, the head of the Global Cyber Alliance, on why in Cybersecurity Awareness Month every business, at least in the UK, should be checking its cybersecurity. Because as the government itself revealed so far this year, 612,000 businesses and 61,000 charities have already had their defenses tested by criminals. The government also offered other advice. It was lampooned about earlier this month when it suggested that businesses should write their recovery strategies down on paper. Yet an essentially intelligent idea if your systems are compromised. It should also be borne in mind that such is the fear about the weakness of the internet that some countries’ embassies have gone back to using fax machines and large financial institutions in the City of London are routinely motorbike-couriering contracts on paper and encrypted CD-ROM to each other. An old-world view that might have sat well in a ’90s TV drama. So it’s telling that the criminals are now also going a little old school. In the M&S attack, the damage was not just financial. Customer data was stolen in the attack. Yet to compound M&S’s embarrassment, The hackers claimed to have sent a ransom demand directly to its chief executive using an employee’s email account, a personalization that is becoming more sinister. A former ransomware negotiator for the cybersecurity company Semperis says he has firsthand knowledge of gang operators using the threat of physical violence as leverage in negotiations. Other people have spoken to executives that have received pictures of family members and school addresses on their phones from suspected gang members. According to Simon Hodgkinson, the former head of cyber for BP and a board advisor for the cybersecurity company Semperis, they are going proper gangster.

Speaker D: We do a ransomware report, and it’s a really consumable report that actually I’d encourage your listeners to all take a look at because it gives you a fairly shocking view of the state of cybersecurity across our businesses. And you know, in the UK and the US, more than 50% of the people and more than 50% of GDP comes from small to medium businesses. And these are the businesses that are being attacked all the time. Okay, I’ll give you a couple of stats. I mean, there’s 78% of responding organizations were targeted with ransomware. This is the shocking stat: 69% of the successful attacks resulted in a ransom payment. So people are paying that, those criminal gangs. That’s just going to encourage more and more and more people to do that. 40% of those attacks, back to things like data, 40% of those attacks came with physical threats. So actually, you know, the actors are now going beyond just the cyber world into threatening people physically because they can get information about where they live, where they work, etc. So you’ve got to be really conscious of that as well. And over 50% of those organizations that paid the ransom paid over $500K, which is just an enormous amount of money. And back to sort of Semperis in particular, every— well, 8 out of 10 of those attacks went after identity identity, because that’s the weakest link. People are not looking after the identity systems in those organizations. They are often hidden in infrastructure, not really got the visibility they need. Once somebody’s actually stolen some credentials and into the identity system, they will sit there, they’ll wait for days, weeks, months, laterally move, and once they’ve got control of your identity system, they can take any of that data.. And it comes back to they can take the data and use that for ransom, they can deploy destructive malware, they can do anything. So what you’ve basically just said is that cyber gangs are involving into protection rackets. They’re going around and they’re saying to people, right, unless you pay us, we’ll break your legs. I mean, another point about this is if you go into the dark web, if you want to compromise an individual, What you do is you get their email address, and quite often they use the same password, and quite often that information is available in the dark web. People just are not getting this, are they? They’re just not aware of the world that they’re living in. Just more and more vulnerabilities within your environment. And then when you put AI on top of that and you say, go discover what you can, Well, it’s not surprising that it comes up with information that you wouldn’t want it to. So I read somewhere a while ago about one of the most searched things through things like Copilot is, what’s the salaries of my executive team? Now, a lot of business processes over time, as you well know, we have applications like Workday and the different HR systems, but a lot of the actual day-to-day work is pulled down into Excel spreadsheets. And done on file servers or SharePoint sites or OneDrive. And people are just letting these, these engines go and discover that information. And then of course, anybody in the organization that has access, because access control isn’t managed properly, then has access to search for that information. So it’s a pretty worrying time. And like I said, it’s just amplifying an attack surface that already exists, but it will be readily available for many more people now. I mean, this is the most terrifying thing, isn’t it? Because people are saying, all right, cybersecurity, we should be really terrified about these AI systems because what will happen is the AI systems will be able to hack us. They will be the ones that we’ll have to be worried about, whereas in fact it’s not. The biggest worry is about the amount of open source information that is out there that can be exploited. Yeah, I agree. I think if you look at most organizations and most people in the world, the type of attack that will compromise them is a drive-by attack. It’ll be an attacker with a financial motivation doing some password spray attack or some, some, you know, huge blast radius attacks to try and compromise credentials. That’s pretty much what they do. Most of the more sophisticated attackers aren’t going to come after Joe Public. They’re not going to come after most organizations. They’re going to have typically focus on things like espionage, potentially disinformation campaigns. So, but actually for most of us, that’s not a concern. It’s the basic foundational stuff. I shouldn’t use the term basic because nothing in technology or cyber is basic, but it’s those foundational controls that you need to put in place to make sure that you’re protecting the assets that you need to protect. And in many cases, that’s data. I would say identity is still a major problem. Every one of our employees, every one of the people are actually vulnerable. And with the increasing sophistication through AI, so AI-generated voices, videos crafted, really, really well-crafted phishing emails, texts, etc. People are more susceptible to that, so there’s a duty of care as a community that we need to educate people. It’s not embarrassing to be phished, and I think as a community we need to adopt a better culture, both in business and more generally. If you think about health and safety, airline safety, oil and gas safety, which is my background clearly. The reason why that improved was we created this culture of speak up where people weren’t scared to say, “I’ve made a mistake,” or people weren’t scared to stop unsafe things happening. I think in the cyber world, we still work in a community where it’s actually, you get vilified for making a mistake. You don’t want to tell your friends that you’ve been phished and lost a bunch of money because it’s embarrassing. But until we create a culture where people feel confident they can speak up because this is the norm, not the exception, I think we will then do a better job of educating the community. That is such a great point, isn’t it? Because one of the things that we really do need is for people to also stand up and say that they’ve been hacked. We do need to get that information right the way across the board. Cyber insurance industry needs it. Because they need to know what the risk is out there. The police and the intelligence agencies need to know that information. So as you say, there is everything to win from being transparent about this, nothing to lose. I agree, and I think one of the great things that’s happening in the industry is the bar is being raised through regulation, but I still think the culture is not there.

Speaker B: Simon Hodgkinson, board advisor to the cybersecurity company Semperis, on the move quite literally by cyber gangs from a part-real, part-internet world known as the omniverse to our doorsteps. It’s a subject that concerns Semperis so much that it’s made a feature film about it with the former CIA head General David Petraeus called Midnight in the War Room. Which explores the escalating cyber conflict between nation-states, criminal groups, and the defenders on the front lines of cyber war. You can find it on www.midnightinthewarroom.com. As it points out, it’s a criminal’s mastery of both the physical and the cyber world that is giving them the edge, enabling them to move swiftly from one world to code to the other to exploit their position. And it’s that that is worrying those combating the cyber gang’s crime wave. They look for weaknesses in code. They literally blast out exploits in huge trolling exercises to see what they can catch. And like a fish, once it’s brought to the surface, they examine it to see what they have caught and how they can exploit it. AI means that they can automate their trolls. They will also use AI tools to identify victims using open source intelligence that has been gathered from social media to look for people in particular organizations and the ways that they might compromise them. And they will also be looking for other smaller organizations that may be linked to the target that they are after so that they can come up through the supply chain according to Clyde Ciprizad, the Senior Vice President and General Manager of Education at the prestigious Linux Foundation.

Speaker E: Well, you know, I think as with so many other things, AI will be used by people with a vested interest, which means that the attackers will be using AI to do increasingly sophisticated social engineering attacks, to do increasingly sophisticated brute force computing attacks on the infrastructure itself. And I think those of us who are trying to defend and protect the integrity of our systems would start to use it more for things like proactive identification of compromised repos, for things like real-time analysis and detection of system intrusions. But it’s not, you know, We keep seeing this movie playing out in technology time and time again, right? Which is the tools themselves are not inherently good or bad. They’re powerful. And then it’s up to us as users to see how are we going to use this and deploy it. So there’s nothing inherent, even for something as powerful as AI, that says it’s a force for good or a force for evil. It’s gonna be used in both ways. And it’s gonna raise this the stakes even higher. I have no doubt that there will be easy-to-implement AI agents that look at patterns of behavior that prompt you if you’re about to add a file to a system that here’s the things you should consider, that prompt you if you’re about to grant access to a network drive to some vendor that you think needs it or complete a transaction But the arms race is on, right? It’s just this is a particularly powerful weapon in the arms race. I’m not sure it changes the fundamental topology of the underlying tension.

Speaker B: Do you think that AI writing code is a problem? A lot of people are saying AI writes bad code and you could use an AI to say, okay, we know that AI writes bad code. Let’s go and look for the holes in the AI bad code. Is this going to be yet another issue?

Speaker E: Well, you know, I think it’s— I’m a bit like a broken record, Peter, in that I keep coming back to the people component, right? What I see people doing is say, have the AI write your code, then have another AI critique the code of the first AI, and then have a third AI critique the code, you know, and so you can get some sort of of circular logic revision. But ultimately, the humans have to decide what are they willing to deploy? When is good enough good enough? What are the things that are sensitive enough that they require heightened scrutiny? Because AI code writing is no different than, you know, typical new uni grad that you’re having write code. They’re gonna do some stuff that’s good, they’re gonna do some stuff that’s atrocious. You’re gonna want to coach it to say, oh, less of this, more of that. And so using it responsibly and recognizing that at least at the current state of affairs, these systems are trained on the past, right? They’re trained on the data that exists that they’ve consumed. And so they’re not really able to hypothesize about really novel threats that aren’t baked into the dataset. That’s already trained them up. Now, if we get to true artificial general intelligence, maybe that changes, but for right now, they are somewhat captive to the data that they were trained on. And we have to recognize that they’re incredibly quick. They’re much faster to get first pass output than your, you know, even seasoned developer. But we know there’s challenges with it. We know the code is long-winded. It’s inelegant at times. It’s prone to certain types of breakdowns. And so they’re using it responsibly and not accepting the first pass, what looks to be sort of hyper-efficient outputting of code as somehow magically in need of no further review is a fool’s errand, right? You have to take responsibility for the code.

Speaker B: Now, you’ve described the world where you say it’s faster. I mean, it almost sounds as though we’re making it more inefficient by having AI check, but I assume that that’s going to be a faster process than a person writing it. What is the threat? Is it that AI can do this, or is it that AI can target individuals better, can approach them with better deepfakes? AI voices now are as good as human voices. They can copy human voices perfectly. So if you can do that with a voice, arguably the video is not going to be that far off. That issue is going to be a big one, isn’t it? Because if you get somebody suddenly ringing you up saying, hey, we’ve been hacked, and you know it’s the head of security and you can hear them on the phone and they say, right, open up this, do this and send this email to that, you could quite easily be stampeded by that.

Speaker E: You can. And I guess I’ll start by promising that I’m a real person and I’m not generated. This touches on another component of what it means to be in the workforce today, which is our tolerance for change and ambiguity is going to have to get a lot, lot higher.

Speaker B: Clyde C. Possette, Senior Vice President and General Manager of Education for the Linux Foundation, the open source software of choice of the internet alternative. And Linux is now the language of choice for 90% of the cloud technology storage that everyone uses. Given that, it’s perhaps no surprise that figures released last week show criminal code attacking open-source software. Software that’s free to use and not proprietary like Apple and Microsoft. Those attacks have surged in the last 3 months according to research from the security research company CyberArk. Sonotype. They said the era of noisy opportunistic malware is over. Attackers are patient, organized, and increasingly using AI to embed themselves inside the very tools developers rely on. They’re hiding malicious payloads in plain sight, turning trusted open-source dependencies into delivery mechanisms for data theft and persistence. Defenders need to match that sophistication with AI-driven visibility and proactive tools that stop threats before they even reach the environment. It’s a development providing further evidence of the accelerating cyber war. The criminals now want data to feed their activities and AI systems, according to Sonatype. And there is a growing trend towards intelligence gathering, espionage, and the monetization of stolen data. It couldn’t be called a drip, drip, drip. The rate of cyber attacks at the moment are more akin to a full-on war on a broad front, a point acknowledged by Ed Lewis, the CEO of the cybersecurity consultancy Syksel. We’ve got now very much in the public consciousness on the front line all of these attacks, not just against big business, but in terms of also how those attacks propagate and cascade down to much smaller entities in supply chain. Okay, what’s the backdrop to all of this, Ed? This, this week alone we’ve seen two attacks— oh, sorry, I mean the Jaguar Land Rover one was earlier. However, We’ve seen 2 attacks and the impact of these is beginning to become significant. I mean, we’ve seen with the Jaguar Land Rover one, we’re seeing an entire supply chain affected. We’re being told that a lot of firms in the UK are impacted by this. The airports attack, what we’re seeing is airports have been disabled. The psychological impact on the population at large with all of this is going to be that there’s a lot of uncertainty that’s been developed. You’re going to get people— we’ve had several incidents that have involved airports, whether they be cyber attacks or fires or whatever. 600% increase in the last 12 months in attacks on the aviation sector. 600%. That’s the statistic that, that was issued by, I think it was ENISA or the NCA over the weekend. And so do you want to go traveling? Do you want to end up stuck in an airport with your kids and all your luggage wondering when you’re going to get back or whether you’re going to cancel the holiday? Exactly. I mean, look, most of the incidents though that we’ve seen in the context of aviation have been groundside, not airside. So I think it’s important that we’re balanced and careful with the message that we send. There is no suggestion that the airline flight safety is at risk here. This is really about the disruption and chaos that’s caused when a backend system, an operational system on the ground, often run by a third party rather than the airport or the airline itself goes down. And what we see when these systems go down is actually the manifestation of something that’s happening beyond aviation across all aspects of our lives. Hugely increased dependency on technology. And that’s great in the sense that it brings huge efficiencies, it speeds things up, it brings commercial advantages, it helps to bring costs down. But the emphasis hasn’t been so much on security as it has on efficiency and commercial gain. And so what we then see is this regression towards processes because we’re having to implement manual human-labored workarounds. We’re seeing a regression to how things once were. So we can see the benefits that technology are bringing. We can see sort of the vulnerabilities also at the same time. And I think actually what it does is shine a light on the need for product safety, product security. The regulation around product security in a cyber context has been scant. Ed Lewis, the CEO of the cyber consultancy Sykesal. As he says, the current situation has been caused by too much too soon. There is a need to check because AI is bringing issues with it. It is a trend that is being dubbed AI slop, and its effects are being felt right the way across the omniverse, from AI-generated content to AI-generated code, much of which is poorly made and has to be checked. An AI problem that’s making the cybersecurity nightmare even worse because the criminals are exploiting some of the things that AI is good at, if it’s properly controlled, according to defense checker Andre Baptista, a white hat hacker, a good guy in technology parlance. Baptista, who is Portuguese, has been hailed as the Cristiano Ronaldo of hacking.

Speaker F: We do ethical hacking, and it’s true that even cyber criminals, nation states, and so on are also using AI. And there are reports, for example, from Trend Micro that report this here. And also, chief information security officers are really aware that this is having an impact on their organizations, for example. And there were reports, as we have been witnessing attacks happening like around 20 minutes after disclosure of a new common vulnerability. That may affect a lot of systems. So what we try to do is to be on the good side of things. We still do hacking, but we do hacking without damaging any system. We do hacking until a certain point so that we can find those vulnerabilities. And then if the organization patch them as soon as possible and is able to prioritize them, then they’ll basically get hacked in an ethical way before the bad guys do it. That doesn’t replace the defensive security, which is more related with detecting these vectors as they happen, but we should also apply and hack ourselves before the bad guys do as well. And that’s something that we basically work on. And we are also combining agentic AI to be able to scale this technology, to be able to scale what pentesters can do. Because in my opinion, we are late into fixing these vulnerabilities and maybe sooner we won’t be able to trust the internet and that would be really bad.

Speaker B: There’s one question that everybody will be pondering about. They’ve been pondering about this for decades and that is why can people keep on finding holes in the code? What is wrong with the code if you can carry on doing this. We’ve seen the attack against Jaguar Land Rover, which everybody’s feeling quite badly in the UK, but we’ve also seen the attack on all of the airports. This is beginning to be destabilizing.

Speaker F: Yeah, I completely agree, and it’s a shame that it’s happening and affecting the availability of systems that we really depend on as a society. Like, even in Portugal, we also had where I live, like, we also have measured these raptions multiple times. And it’s a trend. And I hope it doesn’t grow more than this because we are trying to fight it every day. And we are trying to fight fire with fire. We are basically, as the AI scales for the criminal side, we also try to scale it to understand if we can keep up and be ahead of those threats. But when you talk about the code, And you mentioned, like, what’s the problem with the code? It’s just how it works and it’s just how security works in general. And basically, if you have sufficient code, the vulnerabilities will also exist because we all make mistakes. And even if the code is written by a human or even if it’s written by AI these days, because like around half of the code at Google is already written by an AI, for example. We all make mistakes. We have, and it’s human to make mistakes, and machines also make these kind of mistakes. And it’s just how it works because we cannot achieve 100% security. There’s always a vulnerability that may exist in the code. What we can do is, one, to try to find as much vulnerabilities as possible to make it really difficult and almost impossible. So we are building software faster. And that will increase the attack surfaces of the organizations, right? So obviously, we also need to be able on the analysis side of things to understand that we should also use these kind of tools to scale what we can do and to be able to analyze and test larger portions of code. So basically, we need to keep up in terms of security. We need to keep up with with the technology and the building side of things to find the balance because right now it’s getting a bit unbalanced in my opinion.

Speaker B: Good guy hacker, Andre Baptiste, the organizer of the world’s first AI hacking event, Hack AI Con. If you want to listen to the interviews in full, please go to our websites, www.futureintelligence.co.uk and www.futureintelligence.com. Www.techtv.live. As our interviewees have pointed out, the next wave of cybercrime is going to involve AI deepfakes of images and voices. So it’s even more worrying that voice and psychology research from Queen Mary University of London has found that AI copies of our voices, unlike the AI slop washing around the internet, are now perfect. Here’s Professor Nadine Lavant, the senior lecturer in psychology at Queen Mary’s who carried out the research.

Speaker A: The technology of how we can create synthetic voices has moved on so fast over the last 2 years or so, actually probably a bit longer, but there’s been much, much, much progress such that we have gone from being able to create voices that sound sure, they sound like voices and we can understand them and they sound like people, but we could tell that they were AI-generated voices, to now being able to create voices that really sound like real humans and we cannot tell the difference anymore. You wanted to know why that might be worrying. I guess if you think about implications of this is that if I can take your voice, clone it, and create a deepfake of you from only a few minutes of audio, like I might be able to get from this interview, for example, then there are implications for things like identity theft, scamming, and all of these kinds of things that might arise from these super-realistic voices. But, you know, that’s one side of the coin. There are, of course, also quite amazing opportunities that this technology can open up, basically. Because the technology is still fairly new, There’s so much work to be done. In the end, I have to admit this is not my expertise. I’m a voice perception scientist. I know what people make of these voices. The policy, legal, and ethical end of things, that’s the work my colleagues do, and that’s the work I talk to my colleagues about, and we have interesting discussions around what my findings, which often pertain to, okay, listeners are faced with these things now. What does that mean to them? And how do they perceive these voices, how that can feed into their policy work. But I want to pick up on a thing you just mentioned. What makes synthetic voices, and voices in general, just this very compelling and interesting thing is that often much more so than images of faces or statues or whatever, the voice seems to give people something more. It seems to give them an idea of that there’s still the person actually being there and that there their mind is still there and they can still, I don’t know, be in their presence or something like that. And there’s really interesting work actually from a different, completely different corner, not about AI voices at all, but this is from some business psychologists in the US. And now both their name and affiliation escapes me, so I apologize about that. But what they find basically is that you can give people words written by a person, you can give people those words written and the face of a person in context and everything, but nothing quite makes the content of what is being conveyed to you as information human aside from when you actually add a voice to it. So the voice has this really humanizing quality. So again, benefits and real concerns. We just cannot help as humans but perceive voices as a real thing, even if we know it’s fake. We will tag on information or like a percept that this was a real person to them. And yeah, I find that very fascinating.

Speaker B: That’s an incredibly interesting point, isn’t it?

Speaker D: Because if you think about, let’s look at politics, for example, one of the reasons that the attack was made on Biden was because he didn’t seem to be cognitive. The evidence for that was from his use of words. It’s the use of words that we do focus in on. You know, you can see the light in somebody’s eyes, but it’s how they use voices that we’re really fascinated by. And if you actually also think about it, that’s something, you know, we say it gives voice to something. We use all of these phrases in our language about saying that’s how something is, but to use a word, innovated. It’s where the life is.

Speaker A: The life is in the voice. Yeah, absolutely. And yeah, you know, I need to make my voice heard and things like that. You can just list off more and more examples where you realize that voice in common parlance is basically used as, almost as you as a person and the things you want to express. So, I mean, from a psychology perspective, we actually don’t really have a very good idea of why that is the case. So if you think about it, there’s many things that voices convey.

Speaker B: Queen Mary University of London’s Professor Nadine Lavagne on how voice AI deepfakes can now literally put words into our mouths to deceive others. It’s often said of cybercriminals by the cybercops that they are way ahead of the good guys., and it’s now noticeable that they’re on the cutting edge. While businesses struggle to find ways to adopt AI, the criminals are much more footloose. Businesses want to use AI to replace processes. The criminals have realized that’s not clever. They’re keen to use AI to augment their activities. It’s a trend that Trevor Horvitz, the founder and chief information officer of the cybersecurity security company Trustnet is keen to point out.

Speaker G: There’s an interesting project that exists on the internet where the creators of this project essentially put out a machine that’s unprotected, doesn’t have any antivirus, doesn’t have any sophisticated tools, and they put this machine out there and see how long it takes to get hacked. And it’s always an interesting exercise to see, you know, what is the threat level. And how soon it takes. If you go back 10 years, that system may have taken a day to get hacked, and now you’re looking at literally seconds before that system is found and compromised. So that just tells you the background level of noise that’s happening and the amount of threats that are coming in. But a lot of those are automated threats where people have set up essentially systems to go in and actively look for systems that can be compromised and doing this on an ongoing basis.

Speaker D: Do you recognize, you know, you talk about nation-states, do they have any signature? Can you actually look at an attack as it comes in and say, ah, that’s coming from a certain group of domain names that we know are being used and it’s using those sorts of techniques?

Speaker G: That is correct. Attribution is always a challenge when it comes to cybersecurity to identify who the who the source is and attribute it correctly. But a lot of groups have certain signatures in terms of how they interact and the way they interact, but not necessarily the signals themselves and the sources because those— they use sophisticated mechanisms to hide their source and where the attacks are coming from. And using some of the techniques that I just described where they will compromise the system maybe in a foreign country, and then use that as a stopping-off point. But the signatures of the type of attack and how they construct their attacks is often a telltale sign of the actual source of it, and that’s how cybersecurity forensic analysts identify and be able to accurately attribute an attack to a particular group.

Speaker D: That’s actually quite uncreative of them. What you seem to be suggesting is that The hackers have actually got away with almost a work profile.

Speaker G: Correct, and these sophisticated hacking groups are sophisticated in the way that they put their teams together. They’re very organized. They find particular talents. I mean, you cannot think of cybersecurity and what goes on in cybercrime as being a bunch of hoodlums, you know, working in a basement. There are groups that operate on that basis,, but the more successful ones, the ones who are able to have mass infiltrations, are much more sophisticated than that. Again, a lot of times there is nation-states behind them, so resources is not an issue. But there clearly are recruiters who work to identify resources in institutions. Sometimes they’re coming out of the military, sometimes they’re coming out of universities, but there are active groups who are recruiting hackers either for state-sponsored espionage or for other more nefarious purposes, economic gain. And some of them, it’s a fairly sophisticated mechanism also for how they recruit.

Speaker B: No, look, you’re absolutely right.

Speaker D: I mean, when we were doing the research, we were talking to people in St. Petersburg, and one of the things that the Russian organized crime gangs were doing was monitoring the students in the technical institute in St.

Speaker B: Petersburg to look for technical competence.

Speaker D: So, you know, you’re right, they’re not actually putting out the job adverts, but they are definitely headhunting.

Speaker G: There is an understanding, I think, at a very high level between governments, particularly Western governments, in terms of what, how they interact with one another from a cyber perspective and what type of activities are permitted and not permitted. In terms of gathering intel, and even to the extent with foreign nations about what’s permitted. How far can an organization go before there’ll be retribution?

Speaker B: The world Horvitz described is becoming more akin to a Cold War conflict. A point often made in interviews for this program. It’s an arms race, so there’s echoes of a Second World War submarine conflict. Not quite hand-to-hand, but you suddenly see a cargo ship, the equivalent of a Western company, sunk by a U-boat’s torpedo. It’s a threat that has at last dawned on top-level company executives due to the recent attacks, Horvitz says.

Speaker G: Board-level attention, you know, worldwide from boards are very aware of cyber risk as a major risk to their businesses and their institutions. And because of that, you’re seeing again more investments, more scrutiny on it, both identifying the risk and then putting the controls in place to prevent activities that are unwanted.

Speaker D: Well, there’s definitely a lot more board awareness now as a result of what’s occurred in the last month or so.

Speaker B: Hopefully, things won’t be as worrying as they currently appear.

Speaker D: I mean, one of the points about some of this is going to be, if it continues, that there will be an erosion of trust within the public at large, essentially because psychologically you’ll be wondering if you’re going away on holiday and you’re getting on a plane whether you’re going to be stuck at an airport for 2 days or that something else will go wrong.

Speaker B: I mean, cybersecurity is so essential now that you could actually undermine the trust in so much.

Speaker D: They’re not just the infrastructure, the high street, your car, etc., etc. People really do need to take it seriously.

Speaker G: Yeah, and that comes back again down to ordinary people having protections themselves. But at some level, we have to have some regulation. We have to have government involvement in setting standards for these things. We have it in many, many other parts of our environments. We have it for We have it for our automotive industry. We can take it across public transport. Every part of it has some sort of safety mechanism in place, at least the minimum regulations. When we have that for software, for systems, for companies that provide tools and technologies, I think then we’ll start to see massive improvements in the outcomes from those investments. A lot of organizations are avoiding that and not putting those controls in place. Not putting security in place because of the cost involved. And until we have some baseline regulations, I think we’re going to continue to see this activity grow.

Speaker B: Trevor Horvitz, founder of the cybersecurity company Trustnet, on the desperate need for the technology industry to begin to match other industries in terms of safety, because technology AI is not only mainstream, it’s becoming part of the lifeblood of our world. It’s the very stuff of our universal existence, a point that Password and Tech TV are aiming to underscore with our coverage. This technology needs to be understood and it needs to be transparent so that it can be regulated in everyone’s interests. It’s something that Graham Stewart, the head of public sector at one of the UK’s oldest cybersecurity security companies Check Point says is gradually dawning on people, and quite literally in the last few months. Last May, when the Legal Aid Board was hacked and 200,000 people’s details were stolen, it was relegated to the back pages while Gary Lineker’s exit from the BBC’s Match of the Day football program commanded the headlines. Now In the wake of the Jaguar Land Rover debacle, when the building supply company Travis Perkins has revealed that 100% of its business is in the cloud, there’s a new focus on the importance of cyber. Because Travis Perkins is a supply chain. If it were to become the victim of a ransomware attack like the knights of old, it would vanish. According to Stewart, The materials being used by the software industry need to have similar rules applied to those of the building trade. If you are the bricks and mortar of the new world, then there should be regulations to ensure that, and that those using the technology are aware of what they are doing and the risks involved. It’s time, says Stewart, for us to start calling a spade a spade And a hacker, a ruthless criminal. And forgive me, I invented my own phrase the other day and I’m going to use it here, Pete. It’s the Guy Ritchie-fication of these cyber criminals, right? Okay, there’s a level of glamour that’s pasted onto these people, which I find a bit embarrassing, I’ll be honest with you, because I’m just like, there’s nothing glamorous about knocking over a nursery and stealing kiddies’ details.

Speaker E: There’s nothing glamorous about that. It’s disgusting.

Speaker B: There’s nothing glamorous about affecting the livelihoods and the mortgage payments of thousands and thousands of people, inconveniencing people that are trying to fly. There’s nothing glamorous here, right? These are criminals, pure and simple. What it actually is is that this now, as a topic and thematically, is now front and center in people’s minds. And I’ve absolutely no doubt that last week we were we’re all flat out busy because of the attacks, and it’ll calm down again, and it’ll— but then there’ll be another one, and then there’ll be another one, and then there’ll be another one. And at some point, one has to imagine it will reach a tipping point when governments have to go, okay, enough. And it’s when that tipping point is, and there’s, there’s, there’s a school of thought, and it’s something I’ve talked about for a while is my big fear is the big one, the cyber version of the San Andreas Fault. Graham Stewart, head of public sector at cybersecurity company Check Point, on the need for government to regulate UK businesses to make them more secure against cyber attacks. It’s a problem Mike Puglia says that we can solve if we start dealing with it properly. Piglias, the general manager of Kaseya Labs, a company that you could say is listening out for the telltale signatures of those deadly submerged threats in the internet that I liken to World War II U-boats, because that’s what this world is like. Our attitudes now have to change. Kaseya Labs monitor the omniverse for emerging threats and provide that information to companies. Sounds all very, very spooky. Yet this is information that does not percolate through to smaller organizations and often, according to Puglia, can leave the culprits unpunished because of geopolitical tensions.

Speaker D: It’s a difficult problem because in Those countries that in general, if you talk to any of the intelligence communities, when something big happens, they know exactly who it is and where they are. And if somebody in— a threat actor in Ireland does this against somebody in Canada, Canada will send the info, they’ll extradite them. There’s a lot less of that. It used to be all that, local hackers and things many, many moons ago. But they do this from Russia. I don’t know if that’s involved, but they probably not exactly getting extradited. They might even get a pat on the back. But if you— and the other piece is being— so you’re available 24/7. There are no concerns about getting caught and facing consequences, which is the number one deterrent of crime. But overall, the level is getting higher, you know, the average is getting higher and higher in the number and the impact. What I feel good about is we’re getting more tools. We are starting, as you saw in the UK, the arrests after the M&S, and those people were here, so that’s good, but we need to put more pressure. I’m thinking we’re— this is the tip of the iceberg. We’re starting to see governments actually get involved. They wouldn’t be issuing that joint cyber announcement about telecom networks you know, those— all those countries. So we’re getting there. So I feel good about it. What makes me worried is the amount of shared infrastructure that we have in the supply chain. And what I mean by that, Azure, AWS, Google, there are— a handful of vendors and infrastructures that if badly compromised under this could majorly impact our life. We’ve seen this kind of little piecemeal here and there, but, you know, you look at the top 10 vendors, and quite frankly, I believe they’ve been doing an amazing job that we haven’t seen a massive exploit, and I should knock on wood, of an entire infrastructure, but so many people run on particular software or infrastructure that we all know that more eggs in those baskets, it’ll affect more companies. And that is what concerns me probably the most.

Speaker B: Mike Puglia of Casaya Labs, a company that acts as a listening station for the background hum of criminal activity in the omniverse, on why we have to wise up to the risks that exist in our high-tech world if we are to reap the benefits and avoid the pitfalls. To find out more about how our high-tech worlds work and about their ramifications on society, go to our websites, www.futureintelligence.co.uk and www.techtv.live. You’ve been listening to Password from Future Intelligence, written and presented by me, Peter Warren. Karen, and produced and edited by Blue Buffery.

Speaker A: Thanks for listening and goodbye. This program has been brought to you by Resonance FM. If you like what you heard, please support our work by making a donation at resonancefm.com/donate.

ShareTweet
podnion.com

© Sociaall Inc.

Navigate Site

  • Home
  • Privacy Policy
  • Contact Us

Follow Us

No Result
View All Result
  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
  • Privacy Policy
  • Contact Us

© Sociaall Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00