WEBVTT

1
00:00:00.080 --> 00:00:03.040
<v Speaker 1>Imagine this, right, You find a USB drive in the

2
00:00:03.080 --> 00:00:07.679
<v Speaker 1>parking lot, just lying there. Seems pretty harmless, Yeah, just

3
00:00:07.719 --> 00:00:10.400
<v Speaker 1>a lost drive exactly. So you pick it up, maybe

4
00:00:10.439 --> 00:00:12.759
<v Speaker 1>you're curious, maybe you want to return it. You plug

5
00:00:12.759 --> 00:00:15.720
<v Speaker 1>it into your work computer and boom, just like that,

6
00:00:15.800 --> 00:00:20.640
<v Speaker 1>an entire company's network potentially compromised. It's kind of scary

7
00:00:20.679 --> 00:00:21.679
<v Speaker 1>when you think about it.

8
00:00:21.679 --> 00:00:22.280
<v Speaker 2>It really is.

9
00:00:22.719 --> 00:00:26.120
<v Speaker 1>Welcome to the deep dive. We're pulling back the curtain

10
00:00:26.160 --> 00:00:29.920
<v Speaker 1>today on something both fascinating and frankly a bit chilling.

11
00:00:30.519 --> 00:00:34.159
<v Speaker 1>We're doing a deep dive into social engineering, the art

12
00:00:34.200 --> 00:00:38.200
<v Speaker 1>of psychological warfare, human hacking, persuasion and deception.

13
00:00:38.479 --> 00:00:40.240
<v Speaker 2>It's quite a title, bit it fits.

14
00:00:40.039 --> 00:00:43.159
<v Speaker 1>It really does. Our mission here is to basically break

15
00:00:43.200 --> 00:00:47.640
<v Speaker 1>down how attackers use human psychology, not just software bugs,

16
00:00:47.880 --> 00:00:49.840
<v Speaker 1>to get access to sensitive.

17
00:00:49.359 --> 00:00:51.799
<v Speaker 2>Stuff, and crucially, how you can spot these things.

18
00:00:51.600 --> 00:00:54.960
<v Speaker 1>Exactly, how you can protect yourself, your organization. All our

19
00:00:54.960 --> 00:00:58.479
<v Speaker 1>insights today they come from this really comprehensive document that

20
00:00:58.520 --> 00:00:59.799
<v Speaker 1>details all these techniques.

21
00:01:00.240 --> 00:01:04.319
<v Speaker 2>Yeah, it's eye opening stuff because at its heart, social

22
00:01:04.359 --> 00:01:08.719
<v Speaker 2>engineering it's about getting access to systems, data, even buildings

23
00:01:09.280 --> 00:01:11.920
<v Speaker 2>by playing on our psychology, right.

24
00:01:11.959 --> 00:01:16.120
<v Speaker 1>Using clever non technical tricks instead of like complex hacking.

25
00:01:16.200 --> 00:01:19.359
<v Speaker 2>Precisely, an attacker doesn't need to be some coding wizard.

26
00:01:19.400 --> 00:01:22.519
<v Speaker 2>They could just you know, call you up, pretending to

27
00:01:22.560 --> 00:01:23.799
<v Speaker 2>be it support and.

28
00:01:23.760 --> 00:01:25.159
<v Speaker 1>Try to get your password that way.

29
00:01:25.319 --> 00:01:29.040
<v Speaker 2>Yeah, the main goal always is getting trust, making you

30
00:01:29.040 --> 00:01:29.640
<v Speaker 2>want help them.

31
00:01:29.519 --> 00:01:32.200
<v Speaker 1>Out, So it's less about the code itself and more

32
00:01:32.200 --> 00:01:36.000
<v Speaker 1>about well, the conversation, the persuasion. This idea has been

33
00:01:36.040 --> 00:01:40.200
<v Speaker 1>around forever basically, but it really hit the mainstream in

34
00:01:40.239 --> 00:01:41.799
<v Speaker 1>the nineties, right with Kevin Mitneck.

35
00:01:41.879 --> 00:01:44.480
<v Speaker 2>That's right, he really popularized the term. But yeah, the

36
00:01:44.519 --> 00:01:47.840
<v Speaker 2>concept is ancient, and what's worrying is it's a growing.

37
00:01:47.599 --> 00:01:50.840
<v Speaker 1>Threat because companies are spending fortunes on tech.

38
00:01:50.640 --> 00:01:55.480
<v Speaker 2>Defenses exactly, firewalls, anti virus, all that, but social engineers

39
00:01:55.840 --> 00:01:57.799
<v Speaker 2>they just find clever ways around it. They go for

40
00:01:57.799 --> 00:02:01.799
<v Speaker 2>the people, the human element, which, unfortuate, yeah, often the

41
00:02:01.840 --> 00:02:03.799
<v Speaker 2>weakest link in the whole security.

42
00:02:03.439 --> 00:02:06.200
<v Speaker 1>Chain, and they've got this whole like arsenal of tactics.

43
00:02:06.239 --> 00:02:10.159
<v Speaker 1>One you mentioned in the source. Pretexting sounds kind of serious.

44
00:02:10.719 --> 00:02:11.759
<v Speaker 1>What is that exactly?

45
00:02:11.800 --> 00:02:15.400
<v Speaker 2>Pretexting is, well, it's more than just telling a lie.

46
00:02:15.400 --> 00:02:19.439
<v Speaker 2>It's creating a whole fabricated situation a completely made up scenario, okay,

47
00:02:19.680 --> 00:02:23.400
<v Speaker 2>all designed to steal personal info or gain access. Yeah, so,

48
00:02:23.680 --> 00:02:26.719
<v Speaker 2>like an attacker might pretend to be an IT auditor

49
00:02:26.759 --> 00:02:27.719
<v Speaker 2>from outside.

50
00:02:27.319 --> 00:02:29.479
<v Speaker 1>The company, with the whole backstory and everything.

51
00:02:29.520 --> 00:02:32.759
<v Speaker 2>Oh yeah, really convincing enough to talk their way past security.

52
00:02:32.919 --> 00:02:37.400
<v Speaker 2>Or there's a really disturbing case we found people pretending

53
00:02:37.439 --> 00:02:38.879
<v Speaker 2>to be from a modeling agency.

54
00:02:39.120 --> 00:02:39.840
<v Speaker 1>Oh wow.

55
00:02:39.919 --> 00:02:43.599
<v Speaker 2>Yeah, manipulating women into sending compromising photos, all based on

56
00:02:43.719 --> 00:02:47.560
<v Speaker 2>fake promises, fake interviews, just building trust to exploit them.

57
00:02:47.759 --> 00:02:51.879
<v Speaker 1>That's deeply unsettling how they prey on trust and aspirations

58
00:02:51.960 --> 00:02:52.240
<v Speaker 1>like that.

59
00:02:52.360 --> 00:02:55.240
<v Speaker 2>It really is. The goal is always creating that fake

60
00:02:55.599 --> 00:02:57.960
<v Speaker 2>but believable sense of trust.

61
00:02:58.000 --> 00:03:02.120
<v Speaker 1>But sometimes they're less subtle, right, using like fear or urgency,

62
00:03:02.520 --> 00:03:05.280
<v Speaker 1>which brings us to maybe the most common one, fishing.

63
00:03:05.479 --> 00:03:07.560
<v Speaker 1>I think most people listening are probably run into this.

64
00:03:07.840 --> 00:03:10.719
<v Speaker 2>Oh absolutely, Fishing is definitely the most common. And you

65
00:03:10.759 --> 00:03:13.560
<v Speaker 2>know the signs, right, trying to get personal info, names,

66
00:03:13.639 --> 00:03:16.080
<v Speaker 2>social security numbers, addresses.

67
00:03:15.639 --> 00:03:19.159
<v Speaker 1>Right, using threats or making it seem super urgent.

68
00:03:19.280 --> 00:03:22.280
<v Speaker 2>Yeah, you need to act now. And those suspicious links

69
00:03:22.400 --> 00:03:25.479
<v Speaker 2>taking you to fake websites that look surprisingly real sometimes

70
00:03:25.520 --> 00:03:26.000
<v Speaker 2>and it's.

71
00:03:25.879 --> 00:03:29.599
<v Speaker 1>Weird even emails with bad grammar can still trick.

72
00:03:29.439 --> 00:03:32.800
<v Speaker 2>People, It's true, and they often bundle fishing with malware now,

73
00:03:33.000 --> 00:03:37.680
<v Speaker 2>like getting people to install cracked software from dodgy sources.

74
00:03:37.360 --> 00:03:39.960
<v Speaker 1>Which is actually loaded with malware.

75
00:03:39.439 --> 00:03:43.400
<v Speaker 2>Exactly like those fake Google playbooks apk's mentioned in the source.

76
00:03:44.000 --> 00:03:46.400
<v Speaker 1>So far, it sounds like they're mostly taking stuff, But

77
00:03:46.879 --> 00:03:50.000
<v Speaker 1>do they ever offer something to get what they want,

78
00:03:50.319 --> 00:03:51.120
<v Speaker 1>like a trade?

79
00:03:51.319 --> 00:03:54.599
<v Speaker 2>Definitely. That's where quid pro quote comes in. Literally something

80
00:03:54.639 --> 00:03:57.560
<v Speaker 2>for something, okay, usually offering a service not really goods

81
00:03:57.800 --> 00:04:01.759
<v Speaker 2>in return for information. So the classic is fraudster's calling

82
00:04:01.800 --> 00:04:04.800
<v Speaker 2>pretending to be it offering help. Yeah, offering a quick

83
00:04:04.800 --> 00:04:07.120
<v Speaker 2>fix for some made up computer problem if you just

84
00:04:07.120 --> 00:04:08.599
<v Speaker 2>disable your anti virus first.

85
00:04:09.560 --> 00:04:11.199
<v Speaker 1>I see where this is going right.

86
00:04:11.599 --> 00:04:14.639
<v Speaker 2>Then they install malware, calling it a software update. We

87
00:04:14.719 --> 00:04:18.279
<v Speaker 2>even saw examples of attackers getting office workers passwords for

88
00:04:18.720 --> 00:04:20.199
<v Speaker 2>like a chocolate bar.

89
00:04:20.399 --> 00:04:23.399
<v Speaker 1>Chocolate bar seriously for a password.

90
00:04:23.000 --> 00:04:25.800
<v Speaker 2>Or cheap pen. It shows how little it can sometimes take.

91
00:04:26.040 --> 00:04:29.160
<v Speaker 1>That's wow. It really highlights how easily we can be

92
00:04:29.199 --> 00:04:33.360
<v Speaker 1>swayed sometimes. But beyond direct trades, they also use bait

93
00:04:33.519 --> 00:04:36.399
<v Speaker 1>right with tempting offers. How does baiting work?

94
00:04:36.439 --> 00:04:39.199
<v Speaker 2>Is it just online It's similar off and online. Yeah,

95
00:04:39.240 --> 00:04:42.879
<v Speaker 2>free movie downloads, free music, just enter your log in

96
00:04:42.920 --> 00:04:43.600
<v Speaker 2>details here.

97
00:04:43.879 --> 00:04:44.639
<v Speaker 1>Classic bait.

98
00:04:45.000 --> 00:04:49.040
<v Speaker 2>But it absolutely extends offline too. There's this really interesting

99
00:04:49.079 --> 00:04:53.399
<v Speaker 2>case an organization's founder actually scattered USB drives around the

100
00:04:53.399 --> 00:04:56.639
<v Speaker 2>company parking lot. USB drive yeah, loaded with the trojan virus.

101
00:04:56.920 --> 00:04:59.839
<v Speaker 2>Employees found them, got curious, culled them in, pluged them

102
00:04:59.879 --> 00:05:02.800
<v Speaker 2>in on, which activated a key logger grabbing their log

103
00:05:02.839 --> 00:05:06.279
<v Speaker 2>in details. Shows how powerful simple curiosity can be.

104
00:05:06.439 --> 00:05:09.839
<v Speaker 1>Wow. And then there's one I've definitely seen myself. Tailgating

105
00:05:10.399 --> 00:05:11.000
<v Speaker 1>or piggyback.

106
00:05:11.240 --> 00:05:15.160
<v Speaker 2>Yes, tailgaming. Basically, someone without the right badge or key

107
00:05:15.199 --> 00:05:19.319
<v Speaker 2>card just follows an authorized person into a secure area.

108
00:05:18.920 --> 00:05:20.959
<v Speaker 1>Like holding the door for someone exactly.

109
00:05:21.000 --> 00:05:23.839
<v Speaker 2>The classic is someone dressed as a delivery driver, maybe

110
00:05:23.839 --> 00:05:26.720
<v Speaker 2>carrying a box. They wait for an employee to badge in,

111
00:05:27.199 --> 00:05:29.800
<v Speaker 2>then just ask politely, could you hold the.

112
00:05:29.759 --> 00:05:32.600
<v Speaker 1>Door, And most people would right, just being polite.

113
00:05:33.240 --> 00:05:36.920
<v Speaker 2>It relies on that natural courtesy. It's apparently pretty common

114
00:05:36.920 --> 00:05:40.519
<v Speaker 2>in smaller or medium companies where security might rely more

115
00:05:40.560 --> 00:05:43.399
<v Speaker 2>on oh I recognize that person. We read about one

116
00:05:43.399 --> 00:05:47.079
<v Speaker 2>security tester who tailgated his way through multiple floors of

117
00:05:47.079 --> 00:05:49.759
<v Speaker 2>a building, even into a financial firm's data.

118
00:05:49.639 --> 00:05:52.480
<v Speaker 1>Room and just worked there unnoticed.

119
00:05:51.920 --> 00:05:54.279
<v Speaker 2>For days, gathering info. It's pretty effective.

120
00:05:54.600 --> 00:05:59.399
<v Speaker 1>It's just amazing how these basic human things curiosity, politeness,

121
00:05:59.600 --> 00:06:03.639
<v Speaker 1>trust can be turned against us, even with fancy tech security.

122
00:06:03.759 --> 00:06:06.399
<v Speaker 2>It really shows how deep those social behaviors run.

123
00:06:06.720 --> 00:06:09.199
<v Speaker 1>So with all these different attack methods, who tends to

124
00:06:09.240 --> 00:06:12.160
<v Speaker 1>be the most vulnerable? Who do they target most often?

125
00:06:12.519 --> 00:06:15.800
<v Speaker 2>Well, the analysis we looked at consistently points to new

126
00:06:15.839 --> 00:06:18.759
<v Speaker 2>employees being the most vulnerable. They don't know the ropes yet,

127
00:06:18.839 --> 00:06:21.639
<v Speaker 2>maybe don't know who to trust. That makes sense, followed

128
00:06:21.639 --> 00:06:25.639
<v Speaker 2>by contractors, HR people, executive assistants even it. Staff and

129
00:06:25.720 --> 00:06:29.199
<v Speaker 2>business leaders can be targets. And the problem is a

130
00:06:29.199 --> 00:06:33.160
<v Speaker 2>lot of organizations still don't have you know, solid awareness

131
00:06:33.160 --> 00:06:33.720
<v Speaker 2>programs or.

132
00:06:33.720 --> 00:06:35.759
<v Speaker 1>Training to be getting a big blind spot.

133
00:06:35.639 --> 00:06:40.959
<v Speaker 2>A huge one, and these attacks, they can cost companies thousands,

134
00:06:41.000 --> 00:06:43.079
<v Speaker 2>sometimes millions every year.

135
00:06:43.480 --> 00:06:47.160
<v Speaker 1>It's clear the human factor is huge. But who are

136
00:06:47.160 --> 00:06:50.600
<v Speaker 1>these social engineers? It's not just the stereotype of a

137
00:06:50.639 --> 00:06:51.959
<v Speaker 1>hacker and a hoodie.

138
00:06:51.639 --> 00:06:53.560
<v Speaker 2>Is it. Oh not at all. They come in all

139
00:06:53.560 --> 00:06:57.079
<v Speaker 2>shapes and sizes, some friendly, some malicious. Understanding the players

140
00:06:57.120 --> 00:06:59.680
<v Speaker 2>is pretty key. Okay, So yeah, you have hackers. That's

141
00:06:59.720 --> 00:07:02.680
<v Speaker 2>the which most people have, often blending tech skills with

142
00:07:02.759 --> 00:07:04.439
<v Speaker 2>these personal manipulation skills.

143
00:07:04.439 --> 00:07:07.759
<v Speaker 1>But then there are the ethical ones, penetration testers.

144
00:07:07.360 --> 00:07:09.560
<v Speaker 2>Exactly, pen testers. They have the same kinds of black

145
00:07:09.560 --> 00:07:12.279
<v Speaker 2>hat skills, but they use them for good, to test

146
00:07:12.279 --> 00:07:14.959
<v Speaker 2>a company's defenses, find a holes before the bad.

147
00:07:14.800 --> 00:07:17.560
<v Speaker 1>Guys do, so they're hired to break in essentially.

148
00:07:17.199 --> 00:07:20.560
<v Speaker 2>Pretty much without causing actual harm. Of course, then you've

149
00:07:20.560 --> 00:07:21.600
<v Speaker 2>got identity thieves.

150
00:07:21.680 --> 00:07:23.800
<v Speaker 1>Their game must have evolved a lot.

151
00:07:23.720 --> 00:07:27.120
<v Speaker 2>Oh absolutely really complex impersonations now trying to get all

152
00:07:27.120 --> 00:07:30.879
<v Speaker 2>your personal details name, address, bank info, ss N, birth date.

153
00:07:31.519 --> 00:07:32.319
<v Speaker 2>They use everything they.

154
00:07:32.279 --> 00:07:36.480
<v Speaker 1>Can find and spies of course, deception is their job description, right.

155
00:07:36.759 --> 00:07:41.199
<v Speaker 2>Social engineering is like a massive part of espionage, building trust,

156
00:07:41.519 --> 00:07:44.639
<v Speaker 2>extracting info. It's what they're trained for. But it's not

157
00:07:44.680 --> 00:07:45.800
<v Speaker 2>always outsiders.

158
00:07:46.199 --> 00:07:47.800
<v Speaker 1>You mean disgruntled employees.

159
00:07:47.959 --> 00:07:51.879
<v Speaker 2>Yeah, that's a tricky one because their unhappiness is often hidden.

160
00:07:52.399 --> 00:07:56.319
<v Speaker 2>Employers might miss the signs, like maybe they start volunteering

161
00:07:56.360 --> 00:07:57.040
<v Speaker 2>for extra.

162
00:07:56.839 --> 00:07:59.279
<v Speaker 1>Work and really why it's called protective.

163
00:07:58.879 --> 00:08:01.439
<v Speaker 2>Behavior makes them look loyal, while they might be planning

164
00:08:01.439 --> 00:08:05.040
<v Speaker 2>something where they complained about management a lot, seeking sympathy.

165
00:08:05.199 --> 00:08:08.360
<v Speaker 2>Sometimes they're loners blaming the company, and watch out for

166
00:08:08.399 --> 00:08:13.120
<v Speaker 2>sudden lifestyle changes, big spending, new car, good ego, or

167
00:08:13.160 --> 00:08:14.000
<v Speaker 2>money driving them.

168
00:08:14.240 --> 00:08:17.160
<v Speaker 1>So internal threats are a real danger. And you mentioned

169
00:08:17.160 --> 00:08:21.160
<v Speaker 1>some surprising professions use similar techniques just ethically kind of.

170
00:08:21.240 --> 00:08:25.600
<v Speaker 2>Yeah, think about executive recruiters or good salespeople. They're masters

171
00:08:25.600 --> 00:08:30.160
<v Speaker 2>of elicitation, understanding what motivates people. Scam artists or con

172
00:08:30.240 --> 00:08:33.759
<v Speaker 2>artists are brilliant at spotting victims and playing on greed.

173
00:08:33.879 --> 00:08:36.440
<v Speaker 1>And even governments that's unexpected.

174
00:08:35.960 --> 00:08:40.240
<v Speaker 2>Often overlooked. Yeah, but governments use authority, social proof scarcity

175
00:08:40.279 --> 00:08:44.000
<v Speaker 2>all the time to get messages across influence behavior. Sometimes

176
00:08:44.039 --> 00:08:47.279
<v Speaker 2>it's for good reasons, like public health campaigns, but the

177
00:08:47.360 --> 00:08:51.159
<v Speaker 2>techniques are fundamentally social engineering, making messages stick.

178
00:08:51.440 --> 00:08:53.639
<v Speaker 1>And even fields like psychology or.

179
00:08:53.679 --> 00:09:00.360
<v Speaker 2>Law exactly, psychologists, doctors, lawyers, they all use techniques like elicitation, understanding, psychology,

180
00:09:00.759 --> 00:09:04.519
<v Speaker 2>interviewing tactics to get information from clients, sometimes to manipulate it,

181
00:09:04.679 --> 00:09:08.000
<v Speaker 2>sometimes just to understand it. Really shows social engineering is

182
00:09:08.000 --> 00:09:08.799
<v Speaker 2>almost a science.

183
00:09:08.919 --> 00:09:10.320
<v Speaker 1>There's even an equation for it.

184
00:09:10.399 --> 00:09:14.200
<v Speaker 2>Yeah, the source distilled it down pretext plus attachment, degreed

185
00:09:14.519 --> 00:09:17.759
<v Speaker 2>plus manipulation, target victimized it's methodical.

186
00:09:17.879 --> 00:09:20.039
<v Speaker 1>So with all these different players, what are they actually after?

187
00:09:20.200 --> 00:09:21.120
<v Speaker 1>What's the prize?

188
00:09:21.240 --> 00:09:26.120
<v Speaker 2>It's pretty broad really, passwords obviously, keys, account numbers, access cards,

189
00:09:26.159 --> 00:09:30.480
<v Speaker 2>ID badges, any personal info, details about computer systems, phone lists,

190
00:09:30.720 --> 00:09:35.360
<v Speaker 2>internal websites or servers, intranet stuff, yeah, internet info, and

191
00:09:35.600 --> 00:09:39.919
<v Speaker 2>crucially the names of people who do have access or privileges,

192
00:09:40.399 --> 00:09:42.480
<v Speaker 2>anything that helps them get deeper in or gives them

193
00:09:42.519 --> 00:09:43.000
<v Speaker 2>an edge.

194
00:09:43.039 --> 00:09:44.879
<v Speaker 1>And how do they usually get this stuff. What are

195
00:09:44.879 --> 00:09:46.600
<v Speaker 1>the common tricks we should be looking out for.

196
00:09:46.879 --> 00:09:50.840
<v Speaker 2>Well, one big one now is friending, gating trust on

197
00:09:50.879 --> 00:09:53.080
<v Speaker 2>social media, maybe starting a casual.

198
00:09:52.879 --> 00:09:55.360
<v Speaker 1>Chat to eventually get you to click a bad link.

199
00:09:55.279 --> 00:09:59.159
<v Speaker 2>Right or give up some info malicious attachments links to

200
00:09:59.480 --> 00:10:04.679
<v Speaker 2>fake's eye. Then there's impersonal or social network squatting. Squatting, yeah,

201
00:10:04.720 --> 00:10:07.279
<v Speaker 2>like taking over or spoofing an account of someone you know,

202
00:10:07.879 --> 00:10:10.679
<v Speaker 2>sending you a message, maybe a tweet, pretending to be

203
00:10:10.759 --> 00:10:12.720
<v Speaker 2>them asking for a favor, Hey, can you send me

204
00:10:12.759 --> 00:10:13.440
<v Speaker 2>that spreadsheet?

205
00:10:13.639 --> 00:10:15.480
<v Speaker 1>And because it looks like your friend, you might.

206
00:10:15.399 --> 00:10:20.440
<v Speaker 2>Just do it exactly. Spoofing online identities is worryingly easy sometimes, and.

207
00:10:20.360 --> 00:10:23.279
<v Speaker 1>The classic pretending to be someone on the inside.

208
00:10:23.120 --> 00:10:26.879
<v Speaker 2>Posing as an insider Yeah, impersonating someone from it help desk,

209
00:10:26.960 --> 00:10:30.279
<v Speaker 2>maybe a contractor trying to get passwords or other info.

210
00:10:30.679 --> 00:10:34.039
<v Speaker 2>There was that study mentioned ninety percent of employees in

211
00:10:34.080 --> 00:10:36.720
<v Speaker 2>one company trusted people posing.

212
00:10:36.320 --> 00:10:37.840
<v Speaker 1>As colleagues ninety percent.

213
00:10:37.919 --> 00:10:40.960
<v Speaker 2>Yeah, hand it over sensitive company info just because they

214
00:10:40.960 --> 00:10:43.639
<v Speaker 2>look like they belonged. It's all about playing on that

215
00:10:43.759 --> 00:10:45.879
<v Speaker 2>internal familiarity, that assumption of trust.

216
00:10:46.200 --> 00:10:48.559
<v Speaker 1>Okay, let's shift gears a bit. We've talked about what

217
00:10:48.639 --> 00:10:52.360
<v Speaker 1>they do, but the real magic or dark magic, is

218
00:10:52.399 --> 00:10:55.759
<v Speaker 1>how they mess with our minds. Right, What are the

219
00:10:55.799 --> 00:10:57.720
<v Speaker 1>basic psychological tricks they use.

220
00:10:57.799 --> 00:10:59.799
<v Speaker 2>Yeah, the mind games are key. A big one is

221
00:11:00.360 --> 00:11:04.120
<v Speaker 2>and confidence. Social engineers just act like they belong They

222
00:11:04.240 --> 00:11:05.720
<v Speaker 2>radiate confidence, even.

223
00:11:05.559 --> 00:11:07.120
<v Speaker 1>If they have a fake badge or whatever.

224
00:11:07.320 --> 00:11:10.840
<v Speaker 2>Exactly, it's the posture, the way they carry themselves. It

225
00:11:10.879 --> 00:11:14.720
<v Speaker 2>puts people at ease, makes them seem legit, like concert security.

226
00:11:14.919 --> 00:11:17.919
<v Speaker 2>They look for people acting shifty, not just checking badges.

227
00:11:18.200 --> 00:11:19.879
<v Speaker 2>Confidence is disarming, and.

228
00:11:19.840 --> 00:11:21.799
<v Speaker 1>They probably try to control the conversation.

229
00:11:21.480 --> 00:11:25.600
<v Speaker 2>Right away, definitely. Often by starting with a question, it

230
00:11:25.639 --> 00:11:28.720
<v Speaker 2>immediately puts you slightly on the defensive, make you feel

231
00:11:28.720 --> 00:11:31.919
<v Speaker 2>like you need to respond. They control the flow.

232
00:11:31.679 --> 00:11:34.200
<v Speaker 1>From the start, subtly setting the terms.

233
00:11:34.360 --> 00:11:38.360
<v Speaker 2>Right, and humans, Well, we're wired to return favors, aren't

234
00:11:38.399 --> 00:11:40.120
<v Speaker 2>we That feeling of reciprocation.

235
00:11:40.279 --> 00:11:42.840
<v Speaker 1>Oh yeah, if someone does something nice for you, I.

236
00:11:42.759 --> 00:11:46.120
<v Speaker 2>Feel like you owe them. Social engineers exploit this constantly,

237
00:11:46.399 --> 00:11:49.639
<v Speaker 2>maybe a small gift, a small favor. The source note

238
00:11:49.679 --> 00:11:52.320
<v Speaker 2>of the timing is key. Oh so give a gift

239
00:11:52.320 --> 00:11:54.519
<v Speaker 2>in the morning, then come back in the afternoon asking

240
00:11:54.600 --> 00:11:57.519
<v Speaker 2>for something, maybe claiming they forgot something or there was

241
00:11:57.559 --> 00:12:00.600
<v Speaker 2>a mix up. It feels less like a direct bribe,

242
00:12:00.600 --> 00:12:01.919
<v Speaker 2>then more.

243
00:12:01.840 --> 00:12:04.919
<v Speaker 1>Natural, sneaky, and humor. I bet that helps them seem

244
00:12:05.000 --> 00:12:05.879
<v Speaker 1>likable big time.

245
00:12:06.159 --> 00:12:09.120
<v Speaker 2>Using humor breaks down walls. Yeah, makes them seem friendly,

246
00:12:09.279 --> 00:12:12.039
<v Speaker 2>less threatening. Yeah, helps them get info, maybe talk their

247
00:12:12.080 --> 00:12:13.799
<v Speaker 2>way out of a tight spot, or just charm a

248
00:12:13.840 --> 00:12:17.039
<v Speaker 2>gatekeeper like a security guard. A fake it call might

249
00:12:17.039 --> 00:12:19.519
<v Speaker 2>feel less suspicious if the person on the other end

250
00:12:19.639 --> 00:12:20.480
<v Speaker 2>is cracking jokes.

251
00:12:20.759 --> 00:12:23.080
<v Speaker 1>Okay, this next one you mentioned from the source is wild,

252
00:12:23.360 --> 00:12:27.039
<v Speaker 1>always stating a reason, especially using the word because.

253
00:12:26.919 --> 00:12:29.759
<v Speaker 2>Isn't that fascinating? The copy machine study.

254
00:12:29.559 --> 00:12:30.679
<v Speaker 1>Yeah, tell us about that again.

255
00:12:30.759 --> 00:12:33.639
<v Speaker 2>Okay, so people try to cut in line. If they said,

256
00:12:33.720 --> 00:12:36.279
<v Speaker 2>excuse me, I have five pages. May I use the

257
00:12:36.320 --> 00:12:39.679
<v Speaker 2>machine because I'm in a rush. Ninety four percent let

258
00:12:39.720 --> 00:12:40.120
<v Speaker 2>them cut.

259
00:12:40.440 --> 00:12:41.960
<v Speaker 1>Makes sense. They gave a reason, right.

260
00:12:42.000 --> 00:12:44.200
<v Speaker 2>If they just said, excuse me, I have five pages,

261
00:12:44.240 --> 00:12:48.759
<v Speaker 2>May I use the machine? Only sixty percent agreed. But

262
00:12:48.840 --> 00:12:51.200
<v Speaker 2>here's the crazy part. If they said, excuse me, I

263
00:12:51.240 --> 00:12:53.879
<v Speaker 2>have five pages, May I use the machine because I

264
00:12:53.960 --> 00:12:55.360
<v Speaker 2>need to make copies.

265
00:12:55.240 --> 00:12:57.799
<v Speaker 1>Which is not really a reason at all.

266
00:12:57.879 --> 00:13:01.679
<v Speaker 2>It's totally redundant. But three percent still let them cut

267
00:13:02.039 --> 00:13:03.039
<v Speaker 2>ninety three percent.

268
00:13:03.320 --> 00:13:03.679
<v Speaker 1>Wow.

269
00:13:03.720 --> 00:13:06.200
<v Speaker 2>It shows we often react to the presence of a reason,

270
00:13:06.559 --> 00:13:09.639
<v Speaker 2>the structure of because, not necessarily the logic of the

271
00:13:09.639 --> 00:13:12.840
<v Speaker 2>reason itself, especially if we're stressed or busy. It's like

272
00:13:12.879 --> 00:13:13.840
<v Speaker 2>a mental shortcut.

273
00:13:13.919 --> 00:13:16.960
<v Speaker 1>So any reason is better than no reason. That's powerful

274
00:13:17.120 --> 00:13:17.960
<v Speaker 1>and a bit scary.

275
00:13:18.519 --> 00:13:19.080
<v Speaker 2>It really is.

276
00:13:19.200 --> 00:13:22.559
<v Speaker 1>This leads nicely into elicitation. The source called it subtle

277
00:13:22.600 --> 00:13:26.440
<v Speaker 1>extraction of information during an apparently normal and innocent conversation.

278
00:13:27.120 --> 00:13:28.519
<v Speaker 1>Sounds super hard to spot.

279
00:13:28.759 --> 00:13:31.360
<v Speaker 2>It is very low risk for the attacker, very hard

280
00:13:31.360 --> 00:13:34.120
<v Speaker 2>to detect. You rarely even though you've given anything away.

281
00:13:34.360 --> 00:13:35.399
<v Speaker 1>Why does it work so well?

282
00:13:35.440 --> 00:13:37.440
<v Speaker 2>It plays on basic human nature. We want to be

283
00:13:37.480 --> 00:13:40.159
<v Speaker 2>polite to strangers. We tend to talk more if someone

284
00:13:40.200 --> 00:13:44.039
<v Speaker 2>praises us. Professionals like to sound knowledgeable. We respond if

285
00:13:44.039 --> 00:13:48.159
<v Speaker 2>someone shows concern, and most people don't like to lie outright, so.

286
00:13:48.159 --> 00:13:50.159
<v Speaker 1>They gently pull information.

287
00:13:49.799 --> 00:13:53.360
<v Speaker 2>Out exactly maype you act, even just by answering a

288
00:13:53.440 --> 00:13:57.159
<v Speaker 2>question or nudge you down a certain path. It also

289
00:13:57.200 --> 00:13:59.639
<v Speaker 2>makes their main story, their pretext, seem.

290
00:13:59.480 --> 00:14:01.639
<v Speaker 1>More believer and they have to be really good at

291
00:14:01.679 --> 00:14:02.960
<v Speaker 1>conversation to pull this off.

292
00:14:03.039 --> 00:14:07.639
<v Speaker 2>Oh yeah, masters of it. First, being natural, they have

293
00:14:07.679 --> 00:14:10.039
<v Speaker 2>to sound and act like they belong, like an expert

294
00:14:10.080 --> 00:14:11.039
<v Speaker 2>in whatever role they're.

295
00:14:10.879 --> 00:14:12.559
<v Speaker 1>Playing, and educated on the topic.

296
00:14:12.720 --> 00:14:16.679
<v Speaker 2>Definitely enough knowledge to talk intelligently. Pretending usually doesn't work

297
00:14:16.679 --> 00:14:21.919
<v Speaker 2>for long, and maybe counterintuitively, not being greedy, meaning don't

298
00:14:21.919 --> 00:14:24.639
<v Speaker 2>push too hard for information too quickly, let the target

299
00:14:24.679 --> 00:14:28.840
<v Speaker 2>talk more, be patient. Use that reciprocation principle. Give a

300
00:14:28.840 --> 00:14:32.320
<v Speaker 2>little info, get a little info. Rushing raises red flags.

301
00:14:32.399 --> 00:14:36.840
<v Speaker 1>The source mentions specific elicitation techniques from a DAHS pamphlet.

302
00:14:37.440 --> 00:14:41.720
<v Speaker 2>Yeah, things like ego appeals, subtle flattery, your job sounds

303
00:14:41.759 --> 00:14:46.440
<v Speaker 2>really important, or finding mutual interest. Oh you're into compliance databases,

304
00:14:46.480 --> 00:14:48.879
<v Speaker 2>I was just reading them extends the conversation.

305
00:14:49.159 --> 00:14:51.879
<v Speaker 1>What about deliberate false statements?

306
00:14:52.279 --> 00:14:55.200
<v Speaker 2>That's a clever one. Yeah, you say something wrong on purpose,

307
00:14:55.440 --> 00:14:58.000
<v Speaker 2>knowing the other person will likely correct you with the

308
00:14:58.039 --> 00:14:59.240
<v Speaker 2>real information.

309
00:14:59.120 --> 00:15:01.879
<v Speaker 1>Ah, exploiting the need to be right exactly.

310
00:15:02.320 --> 00:15:06.039
<v Speaker 2>Then there's volunteering information yourself, hoping they'll reciprocate with something

311
00:15:06.120 --> 00:15:10.879
<v Speaker 2>equally valuable. Sets the tone and assume knowledge, acting like

312
00:15:10.919 --> 00:15:13.639
<v Speaker 2>you already know things to get the conversation rolling and

313
00:15:13.759 --> 00:15:15.360
<v Speaker 2>encourage them to add more detail.

314
00:15:15.600 --> 00:15:18.759
<v Speaker 1>And the way they ask questions is critical to totally.

315
00:15:18.799 --> 00:15:21.399
<v Speaker 2>Using open ended questions, what do you think about? Well?

316
00:15:21.440 --> 00:15:24.080
<v Speaker 2>How does that work? Things you can't just answer yes

317
00:15:24.159 --> 00:15:25.879
<v Speaker 2>or no to gets people talking.

318
00:15:25.720 --> 00:15:27.279
<v Speaker 1>The pyramid approach right.

319
00:15:27.240 --> 00:15:31.399
<v Speaker 2>Starting specific and getting broader or the reverse. Then closed

320
00:15:31.480 --> 00:15:34.879
<v Speaker 2>ended questions for specific facts. Is your manager happy with

321
00:15:34.919 --> 00:15:38.559
<v Speaker 2>the project? Leading questions like lawyers use hinting at the

322
00:15:38.600 --> 00:15:41.600
<v Speaker 2>answer and assumptive questions, acting like you already know they

323
00:15:41.639 --> 00:15:42.559
<v Speaker 2>have the info you want.

324
00:15:42.720 --> 00:15:46.120
<v Speaker 1>All these subtle conversational tricks build up to the main act,

325
00:15:46.200 --> 00:15:50.159
<v Speaker 1>which is pretexting, creating that whole fake scenario exactly.

326
00:15:50.200 --> 00:15:52.960
<v Speaker 2>It's the foundation. Yeah, and the first rule of pretexting

327
00:15:53.080 --> 00:15:57.159
<v Speaker 2>is research, research, research. The more they know, the better.

328
00:15:56.919 --> 00:15:59.240
<v Speaker 1>Their chances, and they often target emotions.

329
00:15:59.519 --> 00:16:04.039
<v Speaker 2>Absolutely. Malicious actors are ruthless. They exploit tragedies like nine

330
00:16:04.080 --> 00:16:08.279
<v Speaker 2>to eleven or earthquakes for fake charity scams, or use

331
00:16:08.320 --> 00:16:12.120
<v Speaker 2>celebrity deaths to lure people to bad websites using SEO tricks,

332
00:16:12.120 --> 00:16:14.080
<v Speaker 2>playing on that surge of public interest.

333
00:16:14.399 --> 00:16:17.799
<v Speaker 1>It's pretty dark, really dark, exploiting grief and shock like that.

334
00:16:18.000 --> 00:16:23.080
<v Speaker 2>It is another principle personal interests increase success. It's easier

335
00:16:23.080 --> 00:16:25.320
<v Speaker 2>to fake it if the pretext is something you actually

336
00:16:25.320 --> 00:16:26.039
<v Speaker 2>know about or.

337
00:16:26.039 --> 00:16:27.840
<v Speaker 1>Enjoy less chance of tripping up.

338
00:16:27.879 --> 00:16:31.120
<v Speaker 2>Right avoids that cognitive dissonance in the target where something

339
00:16:31.159 --> 00:16:33.759
<v Speaker 2>just feels off about your story. If you're pretending to

340
00:16:33.759 --> 00:16:35.879
<v Speaker 2>be tech support but look terrified of a server rack,

341
00:16:36.120 --> 00:16:36.960
<v Speaker 2>it won't work.

342
00:16:37.039 --> 00:16:39.360
<v Speaker 1>Like method acting for criminals kind of.

343
00:16:39.519 --> 00:16:43.799
<v Speaker 2>They even practice expressions or dialects, record themselves, try accents

344
00:16:43.799 --> 00:16:47.159
<v Speaker 2>on strangers, and the phone is still huge easy to

345
00:16:47.159 --> 00:16:49.720
<v Speaker 2>spoof caller ID now make it look like the call

346
00:16:49.799 --> 00:16:53.000
<v Speaker 2>is coming from a bank head office, even the white house.

347
00:16:53.320 --> 00:16:55.360
<v Speaker 1>Wow, and simpler is better for the.

348
00:16:55.320 --> 00:17:00.799
<v Speaker 2>Story itself generally, Yes, Simpler pretexts better chances, fewer details

349
00:17:00.799 --> 00:17:04.160
<v Speaker 2>to remember, less chance of contradiction, lets the target fill

350
00:17:04.160 --> 00:17:07.559
<v Speaker 2>in the blanks with their imagination. Sometimes they even make small,

351
00:17:07.599 --> 00:17:11.359
<v Speaker 2>calculated mistakes. Why makes them seem more human, more relatable.

352
00:17:11.640 --> 00:17:15.119
<v Speaker 2>Nobody's perfect. Plus dressing the part helps Khakis and a

353
00:17:15.160 --> 00:17:15.680
<v Speaker 2>polo for.

354
00:17:15.640 --> 00:17:18.759
<v Speaker 1>Tech sport, and it needs to feel natural, not rehearsed exactly.

355
00:17:18.839 --> 00:17:22.559
<v Speaker 2>Pretext should be spontaneous, Use an outline, not a rigid script.

356
00:17:22.839 --> 00:17:26.119
<v Speaker 2>Be flexible, pay attention to the target's reactions and adapt.

357
00:17:26.640 --> 00:17:28.200
<v Speaker 2>Practice makes perfect.

358
00:17:27.839 --> 00:17:29.680
<v Speaker 1>And they don't just grab the info and run.

359
00:17:30.079 --> 00:17:34.400
<v Speaker 2>Usually not, good social engineers provide a follow through or

360
00:17:34.480 --> 00:17:38.599
<v Speaker 2>logical conclusion, like a doctor giving a diagnosis. They wrap

361
00:17:38.680 --> 00:17:41.160
<v Speaker 2>things up, maybe give the target something to do next.

362
00:17:42.000 --> 00:17:45.200
<v Speaker 2>It avoids immediate suspicion. If tech support just walked out

363
00:17:45.240 --> 00:17:48.920
<v Speaker 2>after messing with the database, you get suspicious fast. They

364
00:17:48.960 --> 00:17:50.920
<v Speaker 2>need to close the loop plausibly.

365
00:17:51.400 --> 00:17:54.480
<v Speaker 1>This all feeds into the bigger picture of influence and persuasion,

366
00:17:55.160 --> 00:17:58.079
<v Speaker 1>which sounds less like a trick and more like a science.

367
00:17:58.359 --> 00:18:01.240
<v Speaker 1>Getting someone to think or do you want maybe without

368
00:18:01.240 --> 00:18:02.319
<v Speaker 1>them even noticing it.

369
00:18:02.279 --> 00:18:05.039
<v Speaker 2>Really is a science. The source laid out five key

370
00:18:05.039 --> 00:18:09.599
<v Speaker 2>fundamentals for influence. First, set clear goals. Know exactly what

371
00:18:09.640 --> 00:18:11.319
<v Speaker 2>you want to achieve before you even start.

372
00:18:11.400 --> 00:18:12.839
<v Speaker 1>Have a target in mind, yes.

373
00:18:13.359 --> 00:18:16.599
<v Speaker 2>Second, build rapport quickly connect with the target, get their attention,

374
00:18:17.039 --> 00:18:20.279
<v Speaker 2>maybe even affect their unconscious mind advanced stuff.

375
00:18:20.319 --> 00:18:22.039
<v Speaker 1>They need to be super observant too.

376
00:18:21.960 --> 00:18:25.920
<v Speaker 2>Right absolutely. Third, be observant, aware of yourself, your surroundings,

377
00:18:25.960 --> 00:18:28.960
<v Speaker 2>the target's reactions. Avoid getting lost in your own head

378
00:18:29.079 --> 00:18:32.839
<v Speaker 2>your internal dialogue. Stay present. Fourth, be flexible.

379
00:18:32.960 --> 00:18:35.559
<v Speaker 1>Adapt if things go wrong, exactly.

380
00:18:35.200 --> 00:18:38.000
<v Speaker 2>Like bending a branch, not snapping a steel rod. If

381
00:18:38.000 --> 00:18:42.200
<v Speaker 2>one approach isn't working, change tactics smoothly, don't seem rigid

382
00:18:42.279 --> 00:18:43.599
<v Speaker 2>or unreasonable.

383
00:18:43.240 --> 00:18:45.240
<v Speaker 1>And control their own feeling crucial.

384
00:18:45.799 --> 00:18:48.960
<v Speaker 2>Fifth, be in touch with yourself. Understand and manage your

385
00:18:48.960 --> 00:18:52.359
<v Speaker 2>own emotions. If you secretly hate smoking, it'll be hard

386
00:18:52.400 --> 00:18:56.160
<v Speaker 2>to genuinely persuade someone to quit. Social engineers project the

387
00:18:56.240 --> 00:18:59.119
<v Speaker 2>required emotion, not necessarily their true one.

388
00:18:59.359 --> 00:19:03.119
<v Speaker 1>Okay, on those fundamentals, the source listed eight specific techniques

389
00:19:03.160 --> 00:19:07.200
<v Speaker 1>they use for influence. First one reciprocation. We touched on that.

390
00:19:07.480 --> 00:19:10.599
<v Speaker 2>Yeah, that deep seated need to return favors. They look

391
00:19:10.640 --> 00:19:14.039
<v Speaker 2>for small chances to make you feel indebted subtly.

392
00:19:13.720 --> 00:19:15.599
<v Speaker 1>Then obligation. How's that different?

393
00:19:15.759 --> 00:19:19.039
<v Speaker 2>It's broader, more of a moral or social duty, like

394
00:19:19.279 --> 00:19:21.559
<v Speaker 2>holding a door open leads to the next person holding

395
00:19:21.559 --> 00:19:25.160
<v Speaker 2>the inner door. They might use smart complimenting, give a compliment,

396
00:19:25.279 --> 00:19:28.400
<v Speaker 2>then make a request. Play on that feeling of social obligation.

397
00:19:28.640 --> 00:19:31.200
<v Speaker 1>What about concession giving ground.

398
00:19:31.000 --> 00:19:33.680
<v Speaker 2>Right, yielding on something to make the other person feel

399
00:19:33.680 --> 00:19:36.799
<v Speaker 2>they should yield too, Okay, I'll meet you halfway. They

400
00:19:36.880 --> 00:19:41.240
<v Speaker 2>might label the concession demand reciprocity later or given bit

401
00:19:41.279 --> 00:19:43.119
<v Speaker 2>by bit to keep the exchange.

402
00:19:42.680 --> 00:19:46.440
<v Speaker 1>Going and creating that limited time off or feeling that's scarcity.

403
00:19:46.960 --> 00:19:49.960
<v Speaker 2>Things seem more valuable if they're rare or about to disappear.

404
00:19:50.480 --> 00:19:54.680
<v Speaker 2>Sale ends Friday. Social engineers use this to rush decisions.

405
00:19:54.839 --> 00:19:58.160
<v Speaker 2>Maybe combine it with authority. The CEO needs this fix

406
00:19:58.240 --> 00:19:59.680
<v Speaker 2>by Monday. He's really upset.

407
00:20:00.319 --> 00:20:04.119
<v Speaker 1>Urgency plus authority and authority itself is huge massive.

408
00:20:04.359 --> 00:20:07.319
<v Speaker 2>We're conditioned from childhood to obey authority figures or at

409
00:20:07.400 --> 00:20:11.000
<v Speaker 2>least defer to them. Social engineers fake authority all the time.

410
00:20:11.599 --> 00:20:13.640
<v Speaker 2>Then there's commitment and consistency.

411
00:20:13.920 --> 00:20:15.200
<v Speaker 1>People like to stick to their guns.

412
00:20:15.319 --> 00:20:17.480
<v Speaker 2>Yeah, and they like others to be consistent too. It

413
00:20:17.519 --> 00:20:21.039
<v Speaker 2>makes life simpler. Social engineers appear fully committed to their role.

414
00:20:21.279 --> 00:20:24.720
<v Speaker 2>Their story makes them seem more believable, hardly to doubt

415
00:20:24.759 --> 00:20:25.400
<v Speaker 2>once you start it.

416
00:20:25.440 --> 00:20:28.400
<v Speaker 1>Interacting and just being likingable seems key.

417
00:20:28.720 --> 00:20:32.759
<v Speaker 2>Fundamentally, people are way more easily influenced by people they like,

418
00:20:33.440 --> 00:20:37.680
<v Speaker 2>so social engineers work hard to seem friendly, interested, trustworthy,

419
00:20:38.119 --> 00:20:39.519
<v Speaker 2>makes the whole process smoother.

420
00:20:40.079 --> 00:20:44.240
<v Speaker 1>Finally, social proof or consensus the bandwagon effect.

421
00:20:44.039 --> 00:20:48.799
<v Speaker 2>Exactly everyone else is doing it. In confusing situations, we

422
00:20:48.839 --> 00:20:51.000
<v Speaker 2>look to others to figure out how to act, So

423
00:20:51.039 --> 00:20:53.400
<v Speaker 2>a social engineer might say, oh, lots of people have

424
00:20:53.440 --> 00:20:56.839
<v Speaker 2>given me this info, or most departments handle it this way,

425
00:20:57.279 --> 00:21:00.799
<v Speaker 2>especially powerful when the target is unsure, makes the request

426
00:21:00.839 --> 00:21:02.200
<v Speaker 2>seem normal acceptable.

427
00:21:02.279 --> 00:21:04.519
<v Speaker 1>No, it's definitely not just mind games. They use actual

428
00:21:04.599 --> 00:21:07.000
<v Speaker 1>tools too, right, Beyond a winning smile, Oh.

429
00:21:06.960 --> 00:21:10.799
<v Speaker 2>Yeah, physical tools still matter. Lockpicking isn't dead, especially in

430
00:21:10.799 --> 00:21:15.480
<v Speaker 2>places without fancy electronic locks, and even electronic badges like RFID.

431
00:21:15.160 --> 00:21:16.960
<v Speaker 1>Have issues like the Walmart example.

432
00:21:17.079 --> 00:21:20.119
<v Speaker 2>Right. Inventory tracking is great, but if tags can be

433
00:21:20.160 --> 00:21:23.319
<v Speaker 2>read by anyone, that's a tracking risk. Security is about

434
00:21:23.319 --> 00:21:26.400
<v Speaker 2>the whole system, not just the lock type, and legitimate

435
00:21:26.440 --> 00:21:30.599
<v Speaker 2>auditors use recording devices why to document successful tests, show proof,

436
00:21:30.759 --> 00:21:33.799
<v Speaker 2>and use the footage for training captures all the details.

437
00:21:33.960 --> 00:21:35.720
<v Speaker 2>It's not about shaming, it's about learning.

438
00:21:36.000 --> 00:21:38.039
<v Speaker 1>End phones obviously central.

439
00:21:38.359 --> 00:21:41.160
<v Speaker 2>Absolutely, the phone is still one of the most powerful tools,

440
00:21:41.200 --> 00:21:45.680
<v Speaker 2>easy access, quick interactions, and cell phone vulnerability is high.

441
00:21:46.200 --> 00:21:48.759
<v Speaker 2>We carry so much data and we're often quick to

442
00:21:48.799 --> 00:21:50.559
<v Speaker 2>trust a believable.

443
00:21:50.000 --> 00:21:53.440
<v Speaker 1>Caller, especially with caller ID spoofing Exactly.

444
00:21:53.880 --> 00:21:56.279
<v Speaker 2>Apps on Android and iPhone make it trivial to look

445
00:21:56.319 --> 00:21:59.759
<v Speaker 2>like you're calling from anywhere, head office, the bank, even

446
00:21:59.799 --> 00:22:02.160
<v Speaker 2>the White House, as the source mentioned, makes it really

447
00:22:02.160 --> 00:22:04.079
<v Speaker 2>hard to verify who's actually calling, and.

448
00:22:04.119 --> 00:22:07.440
<v Speaker 1>Software tools must automate a lot of this now for sure.

449
00:22:07.799 --> 00:22:11.039
<v Speaker 2>The Social Engineer Toolkit SCT is a big one. It

450
00:22:11.039 --> 00:22:14.839
<v Speaker 2>helps create malicious emails, PDFs that can make those infected

451
00:22:14.920 --> 00:22:17.359
<v Speaker 2>USB drives we talked about infectious media.

452
00:22:17.160 --> 00:22:18.279
<v Speaker 1>And generate payloads.

453
00:22:18.279 --> 00:22:21.640
<v Speaker 2>What are those payloads are things like reverse shells, basically

454
00:22:21.640 --> 00:22:24.359
<v Speaker 2>code that creates a secret backdoor into a compromised computer,

455
00:22:24.640 --> 00:22:27.440
<v Speaker 2>giving the attack. A remote access set makes this stuff

456
00:22:27.519 --> 00:22:29.279
<v Speaker 2>much easier, even as a web interface.

457
00:22:29.359 --> 00:22:31.599
<v Speaker 1>And tools to guess passwords.

458
00:22:31.319 --> 00:22:35.359
<v Speaker 2>Yeah, password profilers tools like Who's Your Daddy or Common

459
00:22:35.440 --> 00:22:39.319
<v Speaker 2>User Passwords Profiler. They scrape info about a target online

460
00:22:39.440 --> 00:22:42.960
<v Speaker 2>then generate likely passwords based on common habits, birthdays, pet names, etc.

461
00:22:43.480 --> 00:22:45.920
<v Speaker 2>Exploits our tendency to use guessable passwords.

462
00:22:46.240 --> 00:22:51.200
<v Speaker 1>Combining tech with psychology. Okay, let's talk specific scams, those

463
00:22:51.240 --> 00:22:53.640
<v Speaker 1>pickup lines they use, what works on social media?

464
00:22:53.799 --> 00:22:57.119
<v Speaker 2>Oh, the classic friend in trouble scam? Hey, I'm stuck

465
00:22:57.119 --> 00:22:59.279
<v Speaker 2>in New York lost my wallet? Can you wire money?

466
00:23:00.039 --> 00:23:02.799
<v Speaker 2>Usually from a haged account, playing on sympathy totally or

467
00:23:02.920 --> 00:23:05.680
<v Speaker 2>just check out this link looks like it's from a

468
00:23:05.720 --> 00:23:08.799
<v Speaker 2>friend that leads to a dodgy site like that Twitter spam.

469
00:23:08.799 --> 00:23:10.599
<v Speaker 2>Have you seen this video of you? Takes you to

470
00:23:10.640 --> 00:23:12.079
<v Speaker 2>a fake login page.

471
00:23:11.839 --> 00:23:12.720
<v Speaker 1>And the Facebook one.

472
00:23:12.839 --> 00:23:15.119
<v Speaker 2>Someone has a secret crush on you. Download this app

473
00:23:15.119 --> 00:23:19.200
<v Speaker 2>to find out who exploits curiosity, installs malware or adwear,

474
00:23:19.480 --> 00:23:20.519
<v Speaker 2>steals your info?

475
00:23:20.759 --> 00:23:23.920
<v Speaker 1>What about in the actual office face to face stuff?

476
00:23:24.279 --> 00:23:27.200
<v Speaker 2>Common lines like Hi, it's Jack from tech support. We've

477
00:23:27.200 --> 00:23:30.960
<v Speaker 2>detected an infection on your machine, plays on fear, aims

478
00:23:30.960 --> 00:23:35.359
<v Speaker 2>to get passwords or remote access, or someone showing up Hello,

479
00:23:35.440 --> 00:23:38.240
<v Speaker 2>I'm the rep from company X. Here to see mister

480
00:23:38.319 --> 00:23:41.559
<v Speaker 2>Smith looks leg yet might have done their homework. Dress

481
00:23:41.599 --> 00:23:42.200
<v Speaker 2>the part and.

482
00:23:42.160 --> 00:23:43.359
<v Speaker 1>The door holding thing again?

483
00:23:43.640 --> 00:23:46.000
<v Speaker 2>Yeah, excuse me? Can you hold the door? Left my

484
00:23:46.079 --> 00:23:49.359
<v Speaker 2>key card at my desk late for a meeting. Standard tailgating,

485
00:23:49.640 --> 00:23:52.920
<v Speaker 2>often with a fake badge for good measure how many

486
00:23:52.920 --> 00:23:55.599
<v Speaker 2>times will we all just held the door without thinking guilty?

487
00:23:56.119 --> 00:23:59.079
<v Speaker 1>It really does make you pause. Phishing emails still clearly

488
00:23:59.119 --> 00:23:59.640
<v Speaker 1>work too.

489
00:24:00.039 --> 00:24:03.079
<v Speaker 2>Absolutely, things like you want an EVA item but haven't

490
00:24:03.119 --> 00:24:06.720
<v Speaker 2>paid click here plays on worries about your online reputation,

491
00:24:07.160 --> 00:24:09.759
<v Speaker 2>or much worse, you've been laid off. Click here for

492
00:24:09.799 --> 00:24:10.720
<v Speaker 2>sevence details.

493
00:24:11.400 --> 00:24:12.079
<v Speaker 1>That's harsh.

494
00:24:12.200 --> 00:24:16.039
<v Speaker 2>Yeah exploits job insecurity. Digital processes often link to fake

495
00:24:16.200 --> 00:24:18.880
<v Speaker 2>w two forms two trying to get tax info, hits

496
00:24:18.880 --> 00:24:20.599
<v Speaker 2>people where they're vulnerable.

497
00:24:20.160 --> 00:24:22.200
<v Speaker 1>And then the really targeted attacks.

498
00:24:22.160 --> 00:24:28.319
<v Speaker 2>Right exploiting disasters, donate to hurricane relief scams to steal identities,

499
00:24:28.480 --> 00:24:31.359
<v Speaker 2>maybe followed by fake bank calls asking for your SSN.

500
00:24:31.759 --> 00:24:33.920
<v Speaker 2>The Microsoft support calls.

501
00:24:33.599 --> 00:24:35.319
<v Speaker 1>Where they claim your computer has a virus.

502
00:24:35.400 --> 00:24:37.480
<v Speaker 2>Yeah, gets you to open event logs, convince you there's

503
00:24:37.519 --> 00:24:40.799
<v Speaker 2>a problem, then trick you into installing remote access software

504
00:24:40.839 --> 00:24:44.680
<v Speaker 2>like team Viewer so they can install malware. Hijacking trending

505
00:24:44.720 --> 00:24:48.759
<v Speaker 2>Twitter hashtags to redirect people. That really nasty one subject

506
00:24:49.119 --> 00:24:50.920
<v Speaker 2>about your job application.

507
00:24:50.599 --> 00:24:52.920
<v Speaker 1>Sent in reply to real application.

508
00:24:52.599 --> 00:24:56.680
<v Speaker 2>Exactly with malware attached. The FBI warned about one company

509
00:24:56.680 --> 00:24:59.119
<v Speaker 2>losing one hundred and fifty thousand dollars from unauthorized wire

510
00:24:59.160 --> 00:25:02.640
<v Speaker 2>transfers triggered this way, they adapt constantly to what's happening.

511
00:25:02.680 --> 00:25:05.440
<v Speaker 1>The source had some big case studies too, real world examples.

512
00:25:05.599 --> 00:25:08.359
<v Speaker 2>Yeah, the Google and Chinese hackers attack in twenty ten,

513
00:25:08.720 --> 00:25:11.960
<v Speaker 2>super sophisticated, went on for months. The research employees on

514
00:25:11.960 --> 00:25:15.480
<v Speaker 2>social media sent targeted messages from accounts that look like friends,

515
00:25:15.720 --> 00:25:19.559
<v Speaker 2>got spyware installed, and the WikiLeaks stuff Bradley Manning using

516
00:25:19.599 --> 00:25:23.759
<v Speaker 2>a CD labeled Lady Gaga to sneak out classified data,

517
00:25:24.440 --> 00:25:28.240
<v Speaker 2>just lip synching while the data copied. Later attackers used

518
00:25:28.240 --> 00:25:32.279
<v Speaker 2>public interest in wikiliks for phishing PDFs with malicious code,

519
00:25:32.359 --> 00:25:35.880
<v Speaker 2>exploiting Adobe reader flaws, always writing the news.

520
00:25:35.680 --> 00:25:39.640
<v Speaker 1>Cycle, and Facebook had that vulnerability exposed by researchers right.

521
00:25:39.559 --> 00:25:43.480
<v Speaker 2>In twenty eleven, Egyptian researchers built a tool, the Facebook

522
00:25:43.519 --> 00:25:46.759
<v Speaker 2>Profile Dumper. They wanted to show weaknesses, not cause harm,

523
00:25:47.000 --> 00:25:50.440
<v Speaker 2>but the tool could automate creating fake profiles, frending the

524
00:25:50.480 --> 00:25:53.359
<v Speaker 2>target's contacts, cloning the target's profile, and.

525
00:25:53.359 --> 00:25:55.079
<v Speaker 1>Once a friend request was accepted, it.

526
00:25:55.000 --> 00:25:58.400
<v Speaker 2>Could dump all the info and photos accessible through that connection.

527
00:25:59.039 --> 00:26:02.720
<v Speaker 2>It really highlighted laws and Facebook's verification back then showed

528
00:26:02.720 --> 00:26:05.000
<v Speaker 2>how easily. Trust networks could be infiltrated.

529
00:26:05.079 --> 00:26:07.839
<v Speaker 1>Okay, so given all this, it feels overwhelming. How do

530
00:26:07.880 --> 00:26:10.680
<v Speaker 1>we actually protect ourselves? It sounds like nobody is truly immune.

531
00:26:10.799 --> 00:26:13.240
<v Speaker 2>You're right, No organization is totally immune, not even the

532
00:26:13.240 --> 00:26:16.680
<v Speaker 2>White House. Remember that security conference test one hundred and

533
00:26:16.720 --> 00:26:20.119
<v Speaker 2>forty calls, Almost everyone gave up info ninety percent click

534
00:26:20.200 --> 00:26:20.720
<v Speaker 2>the badlink.

535
00:26:20.920 --> 00:26:21.880
<v Speaker 1>So what's the first step?

536
00:26:22.000 --> 00:26:25.599
<v Speaker 2>Learn to discern understand how these attacks work. You don't

537
00:26:25.599 --> 00:26:28.680
<v Speaker 2>need to be an attacker, but knowing the techniques helps

538
00:26:28.720 --> 00:26:32.279
<v Speaker 2>you spot the signs, the weird request, the too good

539
00:26:32.319 --> 00:26:35.759
<v Speaker 2>to be true, offer the pressure tactics. It's like fire

540
00:26:35.799 --> 00:26:36.599
<v Speaker 2>safety for your.

541
00:26:36.440 --> 00:26:39.279
<v Speaker 1>Brain, plan your estate route mentally.

542
00:26:39.119 --> 00:26:43.799
<v Speaker 2>Exactly, be proactive. And for organizations, raising staff awareness is

543
00:26:43.839 --> 00:26:46.720
<v Speaker 2>absolutely critical. Build that security minded culture.

544
00:26:46.759 --> 00:26:48.000
<v Speaker 1>How do you do that effectively?

545
00:26:48.119 --> 00:26:51.559
<v Speaker 2>Make security training interesting? Maybe offer tips for personal security too,

546
00:26:52.000 --> 00:26:55.599
<v Speaker 2>use eye catching posters, change them often. Maybe small rewards

547
00:26:55.599 --> 00:26:59.480
<v Speaker 2>for good security habits, like a clean desk, policy newsletters,

548
00:26:59.519 --> 00:27:03.559
<v Speaker 2>internet pages with clear policies and contacts, regular interactive training,

549
00:27:03.680 --> 00:27:06.519
<v Speaker 2>not just boring lectures. And leadership has to buy in.

550
00:27:06.640 --> 00:27:08.720
<v Speaker 1>Eithers need to walk the walk absolutely.

551
00:27:09.039 --> 00:27:11.279
<v Speaker 2>If the bosses don't care, why should anyone else.

552
00:27:11.400 --> 00:27:13.160
<v Speaker 1>There is that national campaign mentioned too.

553
00:27:13.400 --> 00:27:16.960
<v Speaker 2>Yes, Stom think Connect came out of an Obama era.

554
00:27:17.079 --> 00:27:20.160
<v Speaker 2>Push simple message right, just pause before you play, before

555
00:27:20.200 --> 00:27:23.160
<v Speaker 2>you respond online on any device, take that moment.

556
00:27:23.519 --> 00:27:26.079
<v Speaker 1>Ultimately, it comes down to the individual, the person at

557
00:27:26.119 --> 00:27:26.720
<v Speaker 1>the keyboard.

558
00:27:27.000 --> 00:27:29.839
<v Speaker 2>It really does. Securing the end user, yeah, because that

559
00:27:29.880 --> 00:27:32.799
<v Speaker 2>person is usually the weakest link. The number one rule,

560
00:27:33.279 --> 00:27:37.079
<v Speaker 2>never give out personal info or passwords unnecessarily. Your department

561
00:27:37.119 --> 00:27:41.759
<v Speaker 2>shouldn't need another department's passwords. New systems need new unique credentials.

562
00:27:41.759 --> 00:27:45.319
<v Speaker 2>And remember, legitimate banks or companies will not email or

563
00:27:45.359 --> 00:27:47.519
<v Speaker 2>call you out of the blue asking for your log

564
00:27:47.519 --> 00:27:48.119
<v Speaker 2>in details.

565
00:27:48.160 --> 00:27:50.559
<v Speaker 1>And basic maintenance. Keep software updated.

566
00:27:50.759 --> 00:27:54.240
<v Speaker 2>Such a simple thing but vital. Keep software updated all

567
00:27:54.279 --> 00:27:57.359
<v Speaker 2>the time. Outdated stuff like old browsers or PDF readers

568
00:27:57.960 --> 00:28:01.279
<v Speaker 2>huge security holes, even if you have firewall updates. Patch

569
00:28:01.359 --> 00:28:05.319
<v Speaker 2>those holes. Avoid software known to be insecure. It's basic

570
00:28:05.359 --> 00:28:06.200
<v Speaker 2>digital hygiene.

571
00:28:06.319 --> 00:28:09.440
<v Speaker 1>And you mentioned scripts for employees, not like rigid lines,

572
00:28:09.440 --> 00:28:10.400
<v Speaker 1>but guidelines.

573
00:28:10.480 --> 00:28:13.160
<v Speaker 2>Yeah, outlines to help them handle tricky situations. Gives them

574
00:28:13.160 --> 00:28:16.119
<v Speaker 2>confidence in a process Like that example, call comes in

575
00:28:16.160 --> 00:28:20.279
<v Speaker 2>supposedly from the CEO's office demanding data. The script says,

576
00:28:20.599 --> 00:28:23.160
<v Speaker 2>ask for callers idea in name, ask for project ID.

577
00:28:23.839 --> 00:28:25.920
<v Speaker 2>If they don't provide it, tell them you need manage

578
00:28:25.920 --> 00:28:27.039
<v Speaker 2>your approval via email.

579
00:28:27.240 --> 00:28:29.640
<v Speaker 1>Then hang up empowers the employee.

580
00:28:29.200 --> 00:28:31.799
<v Speaker 2>Exactly, puts them back in control, gives them a safe

581
00:28:31.839 --> 00:28:33.200
<v Speaker 2>way to say no or escalate.

582
00:28:33.519 --> 00:28:37.039
<v Speaker 1>And sometimes companies hire people to test these defenses, right a.

583
00:28:37.039 --> 00:28:41.559
<v Speaker 2>Social engineering audit, a professional security auditor simulates at tax

584
00:28:41.640 --> 00:28:46.720
<v Speaker 2>to test everything policies physical security people. But it's crucial

585
00:28:46.759 --> 00:28:50.640
<v Speaker 2>to remember these auditors are the good guys. They follow rules.

586
00:28:50.880 --> 00:28:53.720
<v Speaker 2>Their goal is to help the company improve, not get

587
00:28:53.720 --> 00:28:54.440
<v Speaker 2>people fired.

588
00:28:54.519 --> 00:28:57.279
<v Speaker 1>And if someone does fall for the audit, the device

589
00:28:57.359 --> 00:28:58.640
<v Speaker 1>is clear, don't fire them.

590
00:28:59.039 --> 00:29:02.039
<v Speaker 2>They've just had a very very powerful, very real lesson.

591
00:29:02.359 --> 00:29:04.640
<v Speaker 2>They're probably now the most security of we're employee. You

592
00:29:04.720 --> 00:29:06.880
<v Speaker 2>have turn it into a learning moment.

593
00:29:07.039 --> 00:29:10.599
<v Speaker 1>This whole deep dive really hammers at home social engineering.

594
00:29:10.640 --> 00:29:12.960
<v Speaker 1>It's not really about the tech, is it. It's about us,

595
00:29:13.000 --> 00:29:13.720
<v Speaker 1>our human.

596
00:29:13.559 --> 00:29:18.720
<v Speaker 2>Nature, politeness, curiosity, wanting to help ego, all the things

597
00:29:18.759 --> 00:29:20.720
<v Speaker 2>that make us human. They just get twisted. It's the

598
00:29:20.799 --> 00:29:23.079
<v Speaker 2>human os they're hacking, not just the computer os.

599
00:29:23.160 --> 00:29:27.400
<v Speaker 1>And understanding these tactics, the elicitation, the pretext, the influenced techniques,

600
00:29:27.599 --> 00:29:29.960
<v Speaker 1>It doesn't just make you safer, does it. It probably

601
00:29:30.000 --> 00:29:32.359
<v Speaker 1>makes you a better communicator, more discerning in.

602
00:29:32.279 --> 00:29:35.720
<v Speaker 2>General, I think so being aware of these dynamics definitely

603
00:29:35.759 --> 00:29:40.279
<v Speaker 2>helps you navigate interactions more effectively, more safely, online and off.

604
00:29:40.839 --> 00:29:42.240
<v Speaker 2>Knowledge is definitely power here.

605
00:29:43.160 --> 00:29:46.920
<v Speaker 1>So as you, our listener, go about your day, think

606
00:29:46.960 --> 00:29:50.400
<v Speaker 1>about your interactions online in person. What subtle favors have

607
00:29:50.480 --> 00:29:53.400
<v Speaker 1>you maybe done recently? What reasons did you accept without

608
00:29:53.400 --> 00:29:56.160
<v Speaker 1>really thinking? How can you use what we've talked about

609
00:29:56.200 --> 00:29:58.480
<v Speaker 1>today to make sure you're the strongest link, not the

610
00:29:58.480 --> 00:30:00.480
<v Speaker 1>weakest one, in your own secure, hardy chain
