WEBVTT

1
00:00:00.120 --> 00:00:03.399
<v Speaker 1>Right, Welcome back everyone, Ready for another deep dive Today.

2
00:00:03.560 --> 00:00:06.400
<v Speaker 1>We're going to be digging into social engineering.

3
00:00:06.559 --> 00:00:08.560
<v Speaker 2>Ooh interesting, which I think.

4
00:00:08.439 --> 00:00:10.320
<v Speaker 1>We all kind of have an idea of what it is, right,

5
00:00:10.679 --> 00:00:13.359
<v Speaker 1>but this is going to be a really fascinating deep dive.

6
00:00:13.640 --> 00:00:18.760
<v Speaker 1>We're using The Social Engineer's Playbook by Jeremiah Talamantes. Have

7
00:00:18.839 --> 00:00:19.719
<v Speaker 1>you ever heard of this book?

8
00:00:19.800 --> 00:00:21.239
<v Speaker 2>I have. It's really interesting.

9
00:00:21.320 --> 00:00:25.120
<v Speaker 1>Yeah. It's packed with like all sorts of crazy statistics

10
00:00:25.160 --> 00:00:27.079
<v Speaker 1>and real world examples and stuff like that.

11
00:00:27.280 --> 00:00:27.480
<v Speaker 3>Yeah.

12
00:00:27.480 --> 00:00:28.920
<v Speaker 2>I think what it does a good job of is

13
00:00:28.920 --> 00:00:32.399
<v Speaker 2>that it highlights how social engineering it goes beyond just

14
00:00:32.439 --> 00:00:34.880
<v Speaker 2>like the hacking, you know, the computers and stuff. It's

15
00:00:34.880 --> 00:00:39.039
<v Speaker 2>about understanding human nature, yeah, and how we can exploit

16
00:00:39.200 --> 00:00:42.759
<v Speaker 2>those those tendencies that we all have right to trust

17
00:00:42.840 --> 00:00:45.960
<v Speaker 2>and be helpful, to be liked to belives exactly.

18
00:00:46.159 --> 00:00:48.039
<v Speaker 1>Yeah, and especially you know in the world that we

19
00:00:48.079 --> 00:00:50.520
<v Speaker 1>live in today, right, Yeah, which is like this hyper

20
00:00:50.560 --> 00:00:52.960
<v Speaker 1>connected world. Like I mean, the book mentions that back

21
00:00:52.960 --> 00:00:56.920
<v Speaker 1>in twenty twelve, thirty seven percent of data breaches involves

22
00:00:56.920 --> 00:01:01.240
<v Speaker 1>social engineering. Wow, that's according to Verizon Data Breach Report.

23
00:01:01.799 --> 00:01:04.079
<v Speaker 2>It's probably only gone up from there. Yeah, And I

24
00:01:04.079 --> 00:01:06.480
<v Speaker 2>think the other thing too, is that you know, we're

25
00:01:06.480 --> 00:01:10.599
<v Speaker 2>not just talking about online scams anymore. Right, Physical social

26
00:01:10.640 --> 00:01:13.439
<v Speaker 2>engineering tactics are on the rise. It's like the con

27
00:01:13.560 --> 00:01:16.719
<v Speaker 2>artist has gone digital in a way. Yeah, because now

28
00:01:16.719 --> 00:01:18.280
<v Speaker 2>you can reach so many more people.

29
00:01:18.640 --> 00:01:20.680
<v Speaker 1>Yeah, So okay, let's just kind of break it down,

30
00:01:20.799 --> 00:01:24.280
<v Speaker 1>like what exactly is social engineering? So the book defines

31
00:01:24.319 --> 00:01:29.200
<v Speaker 1>it as like manipulating people into taking actions or revealing

32
00:01:29.280 --> 00:01:33.280
<v Speaker 1>sensitive information that ultimately goes against their best interests. So

33
00:01:33.560 --> 00:01:35.719
<v Speaker 1>it's really all about the abuse.

34
00:01:35.359 --> 00:01:36.519
<v Speaker 3>Of trust totally.

35
00:01:36.599 --> 00:01:38.879
<v Speaker 2>And that's why it's so important for you listening to

36
00:01:38.879 --> 00:01:41.959
<v Speaker 2>this to understand the different types, right, because it's not

37
00:01:42.040 --> 00:01:43.680
<v Speaker 2>just about oh, I'm not going to fall for that

38
00:01:43.719 --> 00:01:47.680
<v Speaker 2>phishing email. It can affect social engineering can affect anyone anywhere,

39
00:01:47.719 --> 00:01:49.040
<v Speaker 2>and it can take many forms.

40
00:01:49.280 --> 00:01:51.599
<v Speaker 1>Yeah. Like, for instance, the book talks about this security

41
00:01:51.640 --> 00:01:55.959
<v Speaker 1>consultant Steve stasuconis I believe is how you pronounce his name?

42
00:01:56.400 --> 00:02:00.680
<v Speaker 1>Who scottered USB drives labeled payroll or swim suit picks

43
00:02:01.200 --> 00:02:03.680
<v Speaker 1>around a company's entrance? Can you believe that?

44
00:02:03.840 --> 00:02:04.480
<v Speaker 3>Pretty genius?

45
00:02:04.519 --> 00:02:04.799
<v Speaker 1>Actually?

46
00:02:04.840 --> 00:02:08.479
<v Speaker 2>I know, right, if you think about it, it preys

47
00:02:08.560 --> 00:02:12.240
<v Speaker 2>on our innate curiosity, right, like to uncover a mystery

48
00:02:12.560 --> 00:02:15.240
<v Speaker 2>or you know, get a great deal, right.

49
00:02:15.280 --> 00:02:16.919
<v Speaker 1>I mean I have to admit I would be very

50
00:02:16.960 --> 00:02:19.360
<v Speaker 1>tempted me too, Yeah, I would be very tempted to

51
00:02:19.400 --> 00:02:20.639
<v Speaker 1>be like, what's on this thing?

52
00:02:20.879 --> 00:02:22.039
<v Speaker 2>Yeah, like what's on there?

53
00:02:22.360 --> 00:02:24.080
<v Speaker 1>Especially the swimsuit picks? Come on?

54
00:02:24.240 --> 00:02:26.759
<v Speaker 2>Yeah, especially and like who's who are the swimsuit picks of?

55
00:02:26.879 --> 00:02:30.199
<v Speaker 1>Right? Right? Exactly? Yeah. So, I mean it really makes

56
00:02:30.240 --> 00:02:32.879
<v Speaker 1>you realize, you know, just how vulnerable we all are,

57
00:02:33.159 --> 00:02:35.960
<v Speaker 1>absolutely to these kinds of tactics, totally. Yeah.

58
00:02:36.000 --> 00:02:38.879
<v Speaker 2>And I think what makes this even more complex is

59
00:02:38.919 --> 00:02:42.520
<v Speaker 2>the psychology behind it all. So the book actually dedicates

60
00:02:42.560 --> 00:02:47.240
<v Speaker 2>a whole chapter to how social engineers manipulate us using

61
00:02:47.479 --> 00:02:50.280
<v Speaker 2>Robert Saldini's principles of persuasion.

62
00:02:50.360 --> 00:02:53.599
<v Speaker 1>Yeah. So it's not just trickery. It's like understanding, you know,

63
00:02:53.759 --> 00:02:54.759
<v Speaker 1>how our minds work.

64
00:02:54.840 --> 00:02:56.400
<v Speaker 2>It's like they're hacking our brain.

65
00:02:56.360 --> 00:02:57.520
<v Speaker 1>Right exactly, Yet.

66
00:02:57.400 --> 00:03:00.000
<v Speaker 2>Not just our computers, but our actual brains.

67
00:02:59.800 --> 00:03:02.000
<v Speaker 1>The thing about Chaldeani's work, and the reason why it's

68
00:03:02.039 --> 00:03:07.000
<v Speaker 1>so so relevant here is because these are deeply ingrained

69
00:03:07.159 --> 00:03:12.000
<v Speaker 1>persuasive techniques in human behavior totally, right, Like we are

70
00:03:12.199 --> 00:03:14.919
<v Speaker 1>in many ways wired to respond to these.

71
00:03:14.919 --> 00:03:17.199
<v Speaker 2>I don't even realize it, yeah, right exactly.

72
00:03:16.800 --> 00:03:19.800
<v Speaker 1>Which is what makes us such prime targets for social engineers.

73
00:03:20.240 --> 00:03:24.360
<v Speaker 1>So let's dive into some of these tactics one by

74
00:03:24.439 --> 00:03:27.319
<v Speaker 1>one and see how they play out in the real world. Right.

75
00:03:27.919 --> 00:03:30.439
<v Speaker 1>So the first one is reciprocity.

76
00:03:30.759 --> 00:03:34.360
<v Speaker 2>Okay, reciprocity right, So this is the idea, right that

77
00:03:34.439 --> 00:03:36.960
<v Speaker 2>if someone does something nice for you, you almost feel

78
00:03:37.000 --> 00:03:38.479
<v Speaker 2>obligated to return the favor.

79
00:03:38.719 --> 00:03:39.199
<v Speaker 1>Yeah.

80
00:03:39.240 --> 00:03:41.840
<v Speaker 2>The book gives a very specific example which I love,

81
00:03:41.879 --> 00:03:44.680
<v Speaker 2>which is like someone offers to light your cigarette in

82
00:03:44.719 --> 00:03:47.919
<v Speaker 2>a smoking area. Oh interesting, and then later on they

83
00:03:47.960 --> 00:03:49.879
<v Speaker 2>might need to get into a secure area, and so

84
00:03:49.919 --> 00:03:52.120
<v Speaker 2>they ask you, hey, can you hold the door, and

85
00:03:52.120 --> 00:03:54.319
<v Speaker 2>you're like, oh yeah, sure, you know, because they were

86
00:03:54.360 --> 00:03:55.800
<v Speaker 2>nice to you earlier and just trying to be a.

87
00:03:55.719 --> 00:03:58.479
<v Speaker 1>Polite right, And all of a sudden you've given someone

88
00:03:58.520 --> 00:04:01.280
<v Speaker 1>access to like a restricted area or something exactly.

89
00:04:01.280 --> 00:04:01.680
<v Speaker 3>That's it.

90
00:04:01.879 --> 00:04:04.759
<v Speaker 2>So the takeaway for you is to be to be cautious, right,

91
00:04:04.840 --> 00:04:08.319
<v Speaker 2>especially if you're in a security sensitive environment and someone's like, hey,

92
00:04:08.319 --> 00:04:09.759
<v Speaker 2>can I get that for you? Can I do this

93
00:04:09.879 --> 00:04:13.000
<v Speaker 2>for you? Just be cautious, like what's their motivation? Why

94
00:04:13.039 --> 00:04:15.080
<v Speaker 2>are they going out of their way? What's going on?

95
00:04:15.280 --> 00:04:17.120
<v Speaker 1>Yeah, that's a good point. It's easy to get caught

96
00:04:17.199 --> 00:04:19.879
<v Speaker 1>up in the moment, you know, absolutely, and not think

97
00:04:19.920 --> 00:04:22.879
<v Speaker 1>about the bigger picture. Okay, so what about authority?

98
00:04:23.199 --> 00:04:29.040
<v Speaker 2>Authority classic, so we are conditioned right to obey authority

99
00:04:29.079 --> 00:04:30.560
<v Speaker 2>figures even if they're fake.

100
00:04:30.720 --> 00:04:30.959
<v Speaker 1>Yeah.

101
00:04:31.000 --> 00:04:34.160
<v Speaker 2>And so the book uses the example of like the

102
00:04:34.199 --> 00:04:37.319
<v Speaker 2>it guy needs access to the server room, right.

103
00:04:37.160 --> 00:04:38.800
<v Speaker 1>Like, we just I don't know, I feel like our

104
00:04:38.839 --> 00:04:41.800
<v Speaker 1>brains go on autopilot in those situations. It's you you

105
00:04:41.839 --> 00:04:44.319
<v Speaker 1>see a uniform or hear like a voice of authority,

106
00:04:44.360 --> 00:04:46.439
<v Speaker 1>and you're just like, oh, yeah, okay, they must be

107
00:04:46.560 --> 00:04:47.240
<v Speaker 1>legitimate it.

108
00:04:47.360 --> 00:04:51.959
<v Speaker 2>Yeah. And so this really highlights the importance of verifying authority,

109
00:04:52.240 --> 00:04:54.399
<v Speaker 2>you know, don't be afraid, especially when it comes to

110
00:04:54.480 --> 00:04:58.160
<v Speaker 2>like sensitive information or giving someone access to something, ask

111
00:04:58.199 --> 00:05:02.519
<v Speaker 2>for identification, double check with you know, the department. It's

112
00:05:02.639 --> 00:05:04.639
<v Speaker 2>much better to be safe than sorry.

113
00:05:04.480 --> 00:05:07.800
<v Speaker 1>Right, exactly, absolutely, Okay, what about scarcity scarce?

114
00:05:08.360 --> 00:05:11.079
<v Speaker 2>This is where they kind of, you know, social engineers

115
00:05:11.160 --> 00:05:13.079
<v Speaker 2>use a sense of urgency to try to force you

116
00:05:13.160 --> 00:05:16.680
<v Speaker 2>to make a quick decision. So the book gives an

117
00:05:16.720 --> 00:05:20.720
<v Speaker 2>example of like a frantic call from the COO, right,

118
00:05:20.800 --> 00:05:22.759
<v Speaker 2>like the CEO is locked out of their account and

119
00:05:22.759 --> 00:05:25.360
<v Speaker 2>there's a big presentation and they need you to reset

120
00:05:25.399 --> 00:05:26.560
<v Speaker 2>the password right now.

121
00:05:26.639 --> 00:05:27.319
<v Speaker 1>Oh my gosh.

122
00:05:27.480 --> 00:05:30.040
<v Speaker 2>Yeah, you can just imagine that stress and that pressure,

123
00:05:30.160 --> 00:05:31.959
<v Speaker 2>right and you're just like, oh my gosh, I need

124
00:05:32.000 --> 00:05:33.040
<v Speaker 2>to fix this right now.

125
00:05:32.959 --> 00:05:33.600
<v Speaker 1>Right exactly.

126
00:05:33.759 --> 00:05:36.439
<v Speaker 2>You know, So anytime you feel that pressure, those pressure

127
00:05:36.480 --> 00:05:38.639
<v Speaker 2>tactics like that should be a huge red flag, right,

128
00:05:38.800 --> 00:05:43.480
<v Speaker 2>take a breath, verify the situation, and remember that there's

129
00:05:44.000 --> 00:05:47.639
<v Speaker 2>very rarely a true emergency in any of these situations.

130
00:05:48.319 --> 00:05:52.279
<v Speaker 2>It's better to be slightly delayed than to compromise security.

131
00:05:52.519 --> 00:05:57.480
<v Speaker 1>Absolutely. Yeah. Okay, so we've got reciprocity, authority, and scarcity.

132
00:05:57.639 --> 00:05:59.800
<v Speaker 2>What's next next is likability?

133
00:06:00.079 --> 00:06:01.759
<v Speaker 1>Likability Okay, this one's kind.

134
00:06:01.680 --> 00:06:04.560
<v Speaker 2>Of straightforward, which is that we comply with people that

135
00:06:04.600 --> 00:06:07.360
<v Speaker 2>we like or who seem similar to ourselves, right, like human.

136
00:06:07.240 --> 00:06:10.399
<v Speaker 1>Nature to want to like help people we connect with totally.

137
00:06:10.480 --> 00:06:13.120
<v Speaker 2>But this is where it gets true, okay, because be

138
00:06:13.240 --> 00:06:16.560
<v Speaker 2>mindful of how much personal information you're sharing, especially with

139
00:06:16.639 --> 00:06:20.079
<v Speaker 2>people you don't really know, right, even if they seem friendly,

140
00:06:20.519 --> 00:06:23.680
<v Speaker 2>that could be a tactic, right to build that rapport

141
00:06:23.759 --> 00:06:26.000
<v Speaker 2>with you for manipulation later on.

142
00:06:26.279 --> 00:06:30.240
<v Speaker 1>So like set boundaries absolutely, and just you know, don't

143
00:06:30.240 --> 00:06:33.680
<v Speaker 1>be too quick to trust someone just because they seem relatable.

144
00:06:33.759 --> 00:06:35.439
<v Speaker 1>Totally okay, what about concession?

145
00:06:35.600 --> 00:06:39.439
<v Speaker 2>Concession? So this is where a social engineer starts with

146
00:06:39.480 --> 00:06:43.959
<v Speaker 2>a big request and then concedes to something smaller, which

147
00:06:44.000 --> 00:06:46.439
<v Speaker 2>makes you feel like you've won the negotiation.

148
00:06:46.680 --> 00:06:49.720
<v Speaker 1>Right, It's like you're using your own desire to like

149
00:06:50.560 --> 00:06:51.240
<v Speaker 1>compromise it.

150
00:06:51.199 --> 00:06:52.639
<v Speaker 3>Gets exactly, Yeah, that's it.

151
00:06:53.120 --> 00:06:56.439
<v Speaker 2>So really the key here is to recognize any negotiation

152
00:06:56.519 --> 00:07:00.279
<v Speaker 2>where you feel pressured is suspicious, right right, ask yourself,

153
00:07:01.079 --> 00:07:03.160
<v Speaker 2>what are they getting out of this deal? Are you

154
00:07:03.279 --> 00:07:06.519
<v Speaker 2>truly winning or are they manipulating you to get what

155
00:07:06.560 --> 00:07:07.079
<v Speaker 2>they want?

156
00:07:07.279 --> 00:07:10.800
<v Speaker 1>Yeah, so be aware of the power dynamics, Yeah, totally

157
00:07:11.040 --> 00:07:14.560
<v Speaker 1>at play, and don't be free to walk away exactly. Yeah, yeah,

158
00:07:14.639 --> 00:07:17.319
<v Speaker 1>if it feels off, If it feels off, okay. And last,

159
00:07:17.319 --> 00:07:21.160
<v Speaker 1>but not least, on our list of like psychological uh

160
00:07:21.480 --> 00:07:24.000
<v Speaker 1>you know, tactics here is obligation.

161
00:07:24.399 --> 00:07:25.480
<v Speaker 3>Okay. Obligation.

162
00:07:26.199 --> 00:07:29.360
<v Speaker 2>So this is when a social engineer gives you something,

163
00:07:29.519 --> 00:07:32.319
<v Speaker 2>maybe a small gift or some information, to make you

164
00:07:32.399 --> 00:07:33.920
<v Speaker 2>feel indebted to them.

165
00:07:34.160 --> 00:07:37.560
<v Speaker 1>Right, So they're creating a sense of reciprocity.

166
00:07:36.519 --> 00:07:40.439
<v Speaker 2>Exactly before they even like make the ass exactly.

167
00:07:40.720 --> 00:07:41.120
<v Speaker 3>Yeah.

168
00:07:41.160 --> 00:07:44.040
<v Speaker 2>So it's important to be wary of those strings attached,

169
00:07:44.079 --> 00:07:46.360
<v Speaker 2>Like what might they ask for later? Is there a

170
00:07:46.399 --> 00:07:49.160
<v Speaker 2>hidden cost to that free gift or helpful information?

171
00:07:49.480 --> 00:07:53.480
<v Speaker 1>Right? So think critically, yes, and don't let your feelings.

172
00:07:53.079 --> 00:07:54.639
<v Speaker 2>You know, feelings get in the way.

173
00:07:54.600 --> 00:07:58.199
<v Speaker 1>Cloud you judgment. Right. Okay, So I think what's so

174
00:07:58.319 --> 00:08:01.439
<v Speaker 1>fascinating about all this is that these tactics, I mean,

175
00:08:01.480 --> 00:08:03.680
<v Speaker 1>we're talking about them in the context of social engineering,

176
00:08:03.879 --> 00:08:05.959
<v Speaker 1>but they are used in everyday life.

177
00:08:06.000 --> 00:08:08.319
<v Speaker 2>Oh yeah, all the time, all the time, right.

178
00:08:08.240 --> 00:08:10.319
<v Speaker 1>And I'm like already starting to see it.

179
00:08:10.319 --> 00:08:12.680
<v Speaker 2>It's like you put on a whole new lens to

180
00:08:12.759 --> 00:08:13.680
<v Speaker 2>view the world.

181
00:08:13.439 --> 00:08:17.199
<v Speaker 1>Right exactly, Yeah, like how people are trying to influence us. Absolutely,

182
00:08:17.399 --> 00:08:19.759
<v Speaker 1>It's it's a little scary but also like kind of

183
00:08:19.759 --> 00:08:20.560
<v Speaker 1>fascinating to it.

184
00:08:20.560 --> 00:08:21.399
<v Speaker 3>It is fascinating.

185
00:08:21.519 --> 00:08:24.519
<v Speaker 2>Yeah, it's like you can't you can't unsee it once

186
00:08:24.560 --> 00:08:25.399
<v Speaker 2>you start seeing it.

187
00:08:25.480 --> 00:08:29.879
<v Speaker 1>Okay, So we've kind of covered this like psychological foundation,

188
00:08:30.079 --> 00:08:33.399
<v Speaker 1>right of social engineering, But now I'm curious about how,

189
00:08:33.879 --> 00:08:38.080
<v Speaker 1>like how do they actually put these tactics into practice?

190
00:08:38.120 --> 00:08:40.480
<v Speaker 2>So that brings us to like the next one of

191
00:08:40.519 --> 00:08:42.919
<v Speaker 2>the more like intriguing things. I think the book talks

192
00:08:42.960 --> 00:08:46.360
<v Speaker 2>about which is the concept of elicitation. So it's about

193
00:08:46.759 --> 00:08:51.240
<v Speaker 2>subtly extracting information from someone without them realizing.

194
00:08:50.799 --> 00:08:52.399
<v Speaker 3>They're being probed sneaking.

195
00:08:52.519 --> 00:08:54.600
<v Speaker 2>It is, it is, And it's really about asking the

196
00:08:54.679 --> 00:08:59.080
<v Speaker 2>right questions, listening very carefully, and then piecing together, you know,

197
00:08:59.120 --> 00:09:02.519
<v Speaker 2>what seems like in ocuous details to build a bigger picture.

198
00:09:03.000 --> 00:09:06.759
<v Speaker 1>So it's not just being chatty, it's being like strategically chatty.

199
00:09:06.879 --> 00:09:09.080
<v Speaker 2>Yes, it's weaponized chattiness.

200
00:09:08.559 --> 00:09:11.600
<v Speaker 1>Right, exactly. Yeah, And what makes it, I think, so

201
00:09:11.840 --> 00:09:15.559
<v Speaker 1>powerful is that it plays on our natural tendencies to

202
00:09:15.639 --> 00:09:18.600
<v Speaker 1>connect with others, to share information and to.

203
00:09:18.600 --> 00:09:20.039
<v Speaker 3>Help exactly right.

204
00:09:20.159 --> 00:09:22.679
<v Speaker 1>Okay, so let's break down some of these elicitation techniques

205
00:09:23.440 --> 00:09:26.000
<v Speaker 1>that are mentioned in the book. So, one of the

206
00:09:26.000 --> 00:09:27.360
<v Speaker 1>first ones is flattery.

207
00:09:27.559 --> 00:09:28.039
<v Speaker 3>Flattery.

208
00:09:28.240 --> 00:09:31.120
<v Speaker 2>Yeah, so because we all love a little bit of praise, right, Like,

209
00:09:31.159 --> 00:09:34.000
<v Speaker 2>who doesn't like to be like complimented, right, And so

210
00:09:34.039 --> 00:09:35.720
<v Speaker 2>they know how to use it, right, They'll shower you

211
00:09:35.759 --> 00:09:38.799
<v Speaker 2>with compliments, make you feel good about yourself, and therefore

212
00:09:38.840 --> 00:09:41.960
<v Speaker 2>you're much more inclined to open up share information. You know.

213
00:09:42.799 --> 00:09:46.960
<v Speaker 1>It's amazing how like a few well placed compliments can

214
00:09:47.080 --> 00:09:48.639
<v Speaker 1>just like lower our guard.

215
00:09:48.879 --> 00:09:49.519
<v Speaker 3>It really is.

216
00:09:49.639 --> 00:09:50.039
<v Speaker 1>Yeah.

217
00:09:50.399 --> 00:09:53.360
<v Speaker 2>So The takeaway for you is to be wary of flattery, right,

218
00:09:54.039 --> 00:09:57.240
<v Speaker 2>especially from people you don't know well if they're fishing

219
00:09:57.279 --> 00:10:01.480
<v Speaker 2>for details, especially about work or personal life. Be cautious

220
00:10:02.240 --> 00:10:03.480
<v Speaker 2>how much are you revealing?

221
00:10:03.759 --> 00:10:07.960
<v Speaker 1>Keep the bragging in check exact, especially with strangers. Yeah, okay,

222
00:10:07.960 --> 00:10:10.200
<v Speaker 1>So what about false statements?

223
00:10:10.360 --> 00:10:13.960
<v Speaker 2>False statements? So the idea here is that we can't

224
00:10:14.000 --> 00:10:17.679
<v Speaker 2>resist correcting someone who's dead wrong. Oh yeah, that's true,

225
00:10:17.799 --> 00:10:19.720
<v Speaker 2>and then in the process of correcting them, we might

226
00:10:19.759 --> 00:10:22.159
<v Speaker 2>accidentally reveal confidential information.

227
00:10:22.679 --> 00:10:24.960
<v Speaker 1>Yeah that's so true, because you're you know, you're so

228
00:10:25.120 --> 00:10:27.879
<v Speaker 1>focused on setting the record straight total that you don't

229
00:10:27.879 --> 00:10:31.559
<v Speaker 1>even realize you're giving away sensitive information exactly. Yeah, So

230
00:10:31.840 --> 00:10:35.320
<v Speaker 1>just a reminder to be careful about how much insider knowledge. Yeah,

231
00:10:35.399 --> 00:10:37.159
<v Speaker 1>you know you're sharing, even if you think you're just

232
00:10:37.200 --> 00:10:37.799
<v Speaker 1>being helpful.

233
00:10:37.960 --> 00:10:40.679
<v Speaker 2>Totally think about the consequences before you.

234
00:10:40.679 --> 00:10:43.639
<v Speaker 1>Speak, right, exactly, So think before you speak, and don't

235
00:10:43.679 --> 00:10:47.639
<v Speaker 1>let your desire to be right override your sense of security.

236
00:10:47.679 --> 00:10:48.039
<v Speaker 3>Good one.

237
00:10:48.159 --> 00:10:51.240
<v Speaker 1>Yeah, okay, So next, artificial ignorance.

238
00:10:51.480 --> 00:10:54.559
<v Speaker 2>What is that artificial ignorance? This is where a social

239
00:10:54.600 --> 00:10:58.279
<v Speaker 2>engineer plays them okay, to get you to explain things.

240
00:10:58.399 --> 00:11:01.480
<v Speaker 1>Oh, so they're using our helpfulness against it. Yeah.

241
00:11:01.519 --> 00:11:05.600
<v Speaker 2>They might pretend to be unfamiliar with your field or

242
00:11:05.639 --> 00:11:08.799
<v Speaker 2>a particular process, right, and then they're prompting you to

243
00:11:09.039 --> 00:11:13.279
<v Speaker 2>explain it to them, and in the process, you might

244
00:11:13.360 --> 00:11:14.639
<v Speaker 2>reveal something you shouldn't.

245
00:11:14.960 --> 00:11:16.279
<v Speaker 1>Oh. Wow, that's so subtle.

246
00:11:16.360 --> 00:11:16.799
<v Speaker 3>It is subtle.

247
00:11:16.879 --> 00:11:18.639
<v Speaker 1>Yeah, it's like they're leading you down a path but

248
00:11:18.679 --> 00:11:19.840
<v Speaker 1>you don't even realize it.

249
00:11:19.960 --> 00:11:20.399
<v Speaker 3>Exactly.

250
00:11:20.480 --> 00:11:24.840
<v Speaker 2>Yeah, So be wary of overly curious strangers who seem

251
00:11:24.919 --> 00:11:29.399
<v Speaker 2>oddly uninformed about your field could be a ploy to

252
00:11:29.440 --> 00:11:32.759
<v Speaker 2>get you to lower your guard and divulge information you shouldn't.

253
00:11:33.240 --> 00:11:36.720
<v Speaker 1>Yeah. So it's about like trusting our instincts, I know.

254
00:11:36.799 --> 00:11:40.240
<v Speaker 1>Yea if someone's questions, you know, feel a little too probing,

255
00:11:40.480 --> 00:11:43.679
<v Speaker 1>or you know, their lack of knowledge feels suspicious, exactly,

256
00:11:43.840 --> 00:11:47.559
<v Speaker 1>we should be cautious. Okay. Now, sounding board, this is

257
00:11:47.559 --> 00:11:48.279
<v Speaker 1>a new one for me.

258
00:11:48.480 --> 00:11:49.200
<v Speaker 3>Sounding board.

259
00:11:49.320 --> 00:11:51.759
<v Speaker 2>So this is where the social engineer pretends to be

260
00:11:51.840 --> 00:11:56.200
<v Speaker 2>like a sympathetic listener, and so they encourage you to

261
00:11:56.279 --> 00:11:59.120
<v Speaker 2>like vent about your work or brag about your work

262
00:11:59.200 --> 00:12:00.440
<v Speaker 2>or your personal Oh.

263
00:12:00.480 --> 00:12:03.120
<v Speaker 1>So they're like creating a safe space for you.

264
00:12:03.080 --> 00:12:04.279
<v Speaker 2>To overshare exactly.

265
00:12:04.360 --> 00:12:04.600
<v Speaker 1>Okay.

266
00:12:04.639 --> 00:12:08.080
<v Speaker 2>Yeah, and then in the process you're unwittingly revealing information

267
00:12:08.320 --> 00:12:10.840
<v Speaker 2>that could be used against you or your organization.

268
00:12:11.799 --> 00:12:14.480
<v Speaker 1>It's amazing, how like, you know, just having that feeling

269
00:12:15.000 --> 00:12:18.159
<v Speaker 1>that someone's on your side absolutely and just completely lower our.

270
00:12:18.039 --> 00:12:21.120
<v Speaker 2>Guard you can. Yeah, it's a reminder that even venting

271
00:12:21.200 --> 00:12:25.159
<v Speaker 2>or celebrating, like even when you're happy, right, can leak information.

272
00:12:25.600 --> 00:12:29.320
<v Speaker 1>Right, So think twice, Think twice before you open up,

273
00:12:30.039 --> 00:12:31.919
<v Speaker 1>even to people who seem trustworthy.

274
00:12:32.000 --> 00:12:34.440
<v Speaker 2>Yeah, think about the potential consequences, right.

275
00:12:34.320 --> 00:12:37.639
<v Speaker 1>So, like, be mindful of our audience absolutely, even in

276
00:12:37.679 --> 00:12:38.879
<v Speaker 1>casual conversations.

277
00:12:39.080 --> 00:12:40.840
<v Speaker 2>Even casually, we never know who's.

278
00:12:40.559 --> 00:12:42.519
<v Speaker 1>Listening or how they might use that information.

279
00:12:42.720 --> 00:12:43.080
<v Speaker 2>Never know.

280
00:12:43.720 --> 00:12:45.639
<v Speaker 1>Okay, bracketing, this is a weird one.

281
00:12:45.679 --> 00:12:48.960
<v Speaker 2>Bracketing. Yeah, so this is a technique where the social

282
00:12:49.039 --> 00:12:53.399
<v Speaker 2>engineer throws out wild guesses, either too high or too low,

283
00:12:53.960 --> 00:12:56.159
<v Speaker 2>to get you to give a more accurate answer.

284
00:12:56.480 --> 00:12:59.240
<v Speaker 1>Oh. So they're using a process of elimination.

285
00:12:58.879 --> 00:13:01.440
<v Speaker 3>They are, Yeah, they are to narrow it down exactly.

286
00:13:01.639 --> 00:13:04.679
<v Speaker 2>For example, they might say something like I bet your

287
00:13:04.720 --> 00:13:08.600
<v Speaker 2>company has at least five hundred employees, right, and then

288
00:13:08.639 --> 00:13:10.320
<v Speaker 2>you correct them and say, well, actually no, we have

289
00:13:10.360 --> 00:13:11.600
<v Speaker 2>closer to two hundred.

290
00:13:11.960 --> 00:13:15.080
<v Speaker 3>They just elicited you know that's so clever, A good one.

291
00:13:15.159 --> 00:13:16.399
<v Speaker 1>Yeah, I would have never thought of that.

292
00:13:16.600 --> 00:13:17.200
<v Speaker 3>Yeah.

293
00:13:17.360 --> 00:13:20.159
<v Speaker 2>So it's a reminder that if someone's pushing for numbers

294
00:13:20.200 --> 00:13:23.639
<v Speaker 2>or specifics, that's a sign they're not just making casual conversation.

295
00:13:23.960 --> 00:13:28.120
<v Speaker 1>Okay, be cautious. Yeah, so pay attention to the types

296
00:13:28.120 --> 00:13:30.879
<v Speaker 1>of questions people are asking, absolutely, and don't be afraid

297
00:13:30.919 --> 00:13:34.919
<v Speaker 1>to like be vague or evasive if you feel uncomfortable.

298
00:13:34.399 --> 00:13:36.559
<v Speaker 2>Yeah, don't give it to them, right exactly.

299
00:13:36.960 --> 00:13:40.519
<v Speaker 1>Okay. And last, but not least, confidential baiting. This is

300
00:13:40.559 --> 00:13:42.159
<v Speaker 1>the one that like, I don't know it, just it

301
00:13:42.200 --> 00:13:42.879
<v Speaker 1>feels wrong.

302
00:13:43.159 --> 00:13:45.559
<v Speaker 2>It does feel wrong. It's like, come on, Yeah, so

303
00:13:45.639 --> 00:13:48.720
<v Speaker 2>this is where a social engineer shares fake secrets to

304
00:13:48.759 --> 00:13:50.519
<v Speaker 2>get you to reciprocate with real ones.

305
00:13:50.639 --> 00:13:53.799
<v Speaker 1>Oh, it's like they're playing a game of like informational Chicken.

306
00:13:54.120 --> 00:13:55.000
<v Speaker 3>They are, they are.

307
00:13:55.080 --> 00:13:55.320
<v Speaker 1>Yeah.

308
00:13:55.399 --> 00:13:57.519
<v Speaker 2>They'll say something like, just between you and me, I

309
00:13:57.559 --> 00:14:00.559
<v Speaker 2>heard our departments getting a huge budget increase next year.

310
00:14:00.639 --> 00:14:03.639
<v Speaker 2>Oh yeah, And if you're not careful, you might be like, oh, really, well,

311
00:14:03.679 --> 00:14:05.840
<v Speaker 2>I heard we're getting a whole new software.

312
00:14:05.399 --> 00:14:07.799
<v Speaker 1>System, right, you know, just get caught up in.

313
00:14:07.759 --> 00:14:08.279
<v Speaker 3>It, you do.

314
00:14:08.399 --> 00:14:14.279
<v Speaker 2>Yeah, So be extremely cautious. Yeah, shared secrets aren't always confidential, right,

315
00:14:15.039 --> 00:14:16.000
<v Speaker 2>It could be a ploy.

316
00:14:16.320 --> 00:14:20.200
<v Speaker 1>Okay, so the lesson here be very cautious about what

317
00:14:20.240 --> 00:14:22.919
<v Speaker 1>you reveal, absolutely, even if someone else sees to be

318
00:14:22.960 --> 00:14:27.799
<v Speaker 1>sharing sensitive information exactly. Okay, So we've talked about elicitation,

319
00:14:27.960 --> 00:14:31.399
<v Speaker 1>these like sneaky tactics that are designed to get us

320
00:14:31.440 --> 00:14:35.320
<v Speaker 1>to spill the beans without even realizing it. But what

321
00:14:35.440 --> 00:14:39.519
<v Speaker 1>happens when social engineering gets even more theatrical. That's where

322
00:14:39.559 --> 00:14:40.639
<v Speaker 1>pretexting comes in.

323
00:14:40.799 --> 00:14:41.240
<v Speaker 3>You got it.

324
00:14:41.320 --> 00:14:44.240
<v Speaker 2>Pretexting This takes it to a whole new level. It's

325
00:14:44.240 --> 00:14:50.159
<v Speaker 2>about creating believable scenarios sometimes with like fake identities, backstories,

326
00:14:50.240 --> 00:14:53.480
<v Speaker 2>even props, to gain your trust and achieve their goals.

327
00:14:53.720 --> 00:14:56.600
<v Speaker 1>So they're like putting on a performance.

328
00:14:56.320 --> 00:14:59.519
<v Speaker 2>Totally, Yeah, a one man show to deceive their target.

329
00:14:59.679 --> 00:15:02.559
<v Speaker 1>Yeah. It's so crazy wild and so you know, just

330
00:15:02.600 --> 00:15:06.039
<v Speaker 1>like with any good performance, research is key, Like they

331
00:15:06.080 --> 00:15:08.080
<v Speaker 1>have to sound legitimate, right, so they have to know

332
00:15:08.159 --> 00:15:09.279
<v Speaker 1>the lingo, the.

333
00:15:09.200 --> 00:15:12.159
<v Speaker 2>Procedure culture of the organization, and they're trying to infiltrate.

334
00:15:12.360 --> 00:15:16.759
<v Speaker 1>Yeah, it's like they're like method acting, method acting, really

335
00:15:16.759 --> 00:15:19.879
<v Speaker 1>immersing themselves in the role. Okay, so give me the

336
00:15:19.919 --> 00:15:22.879
<v Speaker 1>good stuff, Like what are some of the examples from

337
00:15:22.879 --> 00:15:23.320
<v Speaker 1>the book.

338
00:15:23.799 --> 00:15:26.440
<v Speaker 2>So one of the more simpler ones, right, which I

339
00:15:26.440 --> 00:15:29.480
<v Speaker 2>think is still really effective, is the copyer repair guy

340
00:15:30.120 --> 00:15:34.679
<v Speaker 2>needs mailroom access. It's all about appearances, right, and assumptions.

341
00:15:34.960 --> 00:15:36.919
<v Speaker 1>You see someone in a uniform.

342
00:15:36.799 --> 00:15:38.559
<v Speaker 3>Yeah, exactly.

343
00:15:38.159 --> 00:15:41.639
<v Speaker 1>Carrying a toolbox, like, Okay, this person's probably legit, exactly,

344
00:15:41.679 --> 00:15:43.480
<v Speaker 1>even if something feels slightly off.

345
00:15:43.360 --> 00:15:45.600
<v Speaker 2>Even if yeah, and then you're like, oh.

346
00:15:45.320 --> 00:15:49.399
<v Speaker 1>Man, it's amazing how our own expectations can fool us totally.

347
00:15:50.120 --> 00:15:51.240
<v Speaker 3>Yeah, it's wild.

348
00:15:51.679 --> 00:15:55.320
<v Speaker 2>The book also mentions the irs audit notice email this

349
00:15:55.440 --> 00:15:57.600
<v Speaker 2>plays on our fear and urgency.

350
00:15:58.039 --> 00:16:00.639
<v Speaker 1>Just those two words are enough to send like.

351
00:16:01.200 --> 00:16:04.919
<v Speaker 2>Shivers sends me into a cold sweat.

352
00:16:04.600 --> 00:16:07.279
<v Speaker 1>Oh my gosh. Yeah yeah. Yeah, so they're exploiting that

353
00:16:07.360 --> 00:16:08.159
<v Speaker 1>fear totally.

354
00:16:08.240 --> 00:16:09.840
<v Speaker 3>Yeah, right, absolutely.

355
00:16:10.120 --> 00:16:13.519
<v Speaker 1>Okay, so even the most official looking emails.

356
00:16:13.399 --> 00:16:14.080
<v Speaker 3>Ken be fake.

357
00:16:14.320 --> 00:16:17.559
<v Speaker 2>Yeah, so always double check the sender, look for any

358
00:16:17.600 --> 00:16:21.000
<v Speaker 2>red flags, and never click on links or attachments that

359
00:16:21.039 --> 00:16:21.919
<v Speaker 2>you weren't expecting.

360
00:16:22.200 --> 00:16:24.960
<v Speaker 1>Yeah, and actually this is a good place to stop

361
00:16:25.000 --> 00:16:27.000
<v Speaker 1>for now, and we will pick up this conversation in

362
00:16:27.039 --> 00:16:27.519
<v Speaker 1>part two.

363
00:16:28.240 --> 00:16:30.759
<v Speaker 2>Okay, So where were we? Oh yeah, talking about some

364
00:16:30.799 --> 00:16:34.120
<v Speaker 2>of these crazy social engineering tactics The book actually has

365
00:16:34.120 --> 00:16:36.240
<v Speaker 2>this whole chapter. It calls it the playbook.

366
00:16:36.320 --> 00:16:38.279
<v Speaker 1>Oh yeah, it's like literally a playbook.

367
00:16:38.320 --> 00:16:41.240
<v Speaker 2>It is like a cheat sheet for how to like

368
00:16:41.440 --> 00:16:44.879
<v Speaker 2>manipulate people, right, all these different pretexts.

369
00:16:44.919 --> 00:16:45.759
<v Speaker 3>It's pretty wild.

370
00:16:45.799 --> 00:16:48.600
<v Speaker 2>It's like you almost have to admire the creativity, but

371
00:16:48.679 --> 00:16:51.080
<v Speaker 2>also like knowing about it is the first step to

372
00:16:51.240 --> 00:16:53.200
<v Speaker 2>protecting yourself, right exactly.

373
00:16:53.279 --> 00:16:56.559
<v Speaker 1>Yeah. Yeah, So walk me through some of these plays, like,

374
00:16:56.639 --> 00:16:59.639
<v Speaker 1>you know, what kind of scenarios should we be on

375
00:16:59.639 --> 00:17:00.320
<v Speaker 1>the look for.

376
00:17:00.799 --> 00:17:04.920
<v Speaker 2>So one that's incredibly common and still super effective is

377
00:17:05.559 --> 00:17:07.720
<v Speaker 2>like the security bulletin email.

378
00:17:08.000 --> 00:17:08.680
<v Speaker 3>It looks like.

379
00:17:08.680 --> 00:17:12.880
<v Speaker 2>It's coming from you know, Microsoft, your anti virus provider.

380
00:17:12.960 --> 00:17:14.079
<v Speaker 1>Oh yeah, yeah, I've seen those.

381
00:17:14.160 --> 00:17:17.319
<v Speaker 2>You've seen those. Yeah, and they're warning you, like about

382
00:17:17.359 --> 00:17:20.960
<v Speaker 2>some critical security vulnerability, you know, try to scare you

383
00:17:21.000 --> 00:17:24.279
<v Speaker 2>into clicking a link or opening an attachment to fix

384
00:17:24.359 --> 00:17:24.920
<v Speaker 2>the problem.

385
00:17:25.039 --> 00:17:27.680
<v Speaker 1>Yeah. Yeah. It's like using your own good intention against

386
00:17:27.720 --> 00:17:29.960
<v Speaker 1>you totally, right, Like I'm just trying to be a

387
00:17:30.039 --> 00:17:32.519
<v Speaker 1>responsible digital citizen exactly.

388
00:17:32.559 --> 00:17:35.160
<v Speaker 2>You're trying to be safe, right yeah, and they're exploiting that.

389
00:17:35.720 --> 00:17:37.440
<v Speaker 1>Okay, what else? What else?

390
00:17:37.480 --> 00:17:37.759
<v Speaker 3>Okay?

391
00:17:38.160 --> 00:17:42.359
<v Speaker 2>Bank security email alert they're posing as you know, a

392
00:17:42.400 --> 00:17:46.200
<v Speaker 2>bank representative emailing you about suspicious activity on your account.

393
00:17:46.240 --> 00:17:48.759
<v Speaker 1>I've gotten those two. Yeah, they always like make it

394
00:17:48.799 --> 00:17:49.799
<v Speaker 1>sound super urgent.

395
00:17:49.920 --> 00:17:51.960
<v Speaker 2>Oh yeah, they always do, right, Like you need to

396
00:17:52.039 --> 00:17:55.480
<v Speaker 2>act immediately to prevent fraud, right right, right, And so

397
00:17:55.839 --> 00:17:58.680
<v Speaker 2>they want you to act quickly without thinking. Yeah, you know,

398
00:17:58.720 --> 00:18:02.200
<v Speaker 2>they might ask you to open attachment supposedly to review

399
00:18:02.200 --> 00:18:05.000
<v Speaker 2>the transactions, but it's actually loaded with malware.

400
00:18:05.279 --> 00:18:08.319
<v Speaker 1>Oh yeah. They play on our you know, financial anxieties,

401
00:18:08.400 --> 00:18:10.559
<v Speaker 1>like we're so worried about our money being stolen.

402
00:18:10.720 --> 00:18:11.039
<v Speaker 2>Totally.

403
00:18:11.079 --> 00:18:12.160
<v Speaker 3>It's like a primal fear.

404
00:18:12.319 --> 00:18:16.160
<v Speaker 1>Yeah, okay, so what about I mean this is like

405
00:18:16.720 --> 00:18:20.440
<v Speaker 1>the granddaddy of all the fear inducing emails, the IRS

406
00:18:20.440 --> 00:18:21.319
<v Speaker 1>audit notice.

407
00:18:21.480 --> 00:18:23.200
<v Speaker 3>Oh yeah, that one's a classic.

408
00:18:23.359 --> 00:18:25.359
<v Speaker 2>I don't think there's anyone out there who wouldn't feel

409
00:18:25.400 --> 00:18:27.119
<v Speaker 2>at least a little bit of dread, right.

410
00:18:27.119 --> 00:18:29.680
<v Speaker 1>I mean those two words irs audit are enough to, like,

411
00:18:30.279 --> 00:18:32.559
<v Speaker 1>I don't know, make me want to just crawl under

412
00:18:32.559 --> 00:18:33.279
<v Speaker 1>a rocket too.

413
00:18:33.359 --> 00:18:35.680
<v Speaker 2>Yeah, like sends me to a cold sweat, like get

414
00:18:35.720 --> 00:18:38.519
<v Speaker 2>me out of here exactly. So of course they know

415
00:18:38.599 --> 00:18:42.079
<v Speaker 2>that they'll exploit that fear, claiming you've been selected for

416
00:18:42.160 --> 00:18:45.039
<v Speaker 2>an audit, right, and then you have to open an attachment,

417
00:18:45.359 --> 00:18:49.079
<v Speaker 2>oh yeah, for more information. Of course, the attachment malicious

418
00:18:49.640 --> 00:18:51.079
<v Speaker 2>designed a compromiser system.

419
00:18:51.440 --> 00:18:54.079
<v Speaker 1>Okay, so this is just a good reminder, right, Like

420
00:18:54.519 --> 00:18:57.200
<v Speaker 1>even the most official looking emails can be faked.

421
00:18:57.240 --> 00:19:00.400
<v Speaker 2>Oh yeah, totally always double check the center for any

422
00:19:00.440 --> 00:19:04.599
<v Speaker 2>red flex Verify, Verify verify exactly. Don't click on links

423
00:19:04.680 --> 00:19:06.599
<v Speaker 2>or attachments you weren't expecting.

424
00:19:06.240 --> 00:19:09.039
<v Speaker 1>Right, Okay, So I mean even those of us who

425
00:19:09.079 --> 00:19:12.880
<v Speaker 1>are like, you know, pretty tech savvy, right, can still

426
00:19:13.359 --> 00:19:16.519
<v Speaker 1>fall prey to these things. What about, Like, I'm curious,

427
00:19:16.920 --> 00:19:20.440
<v Speaker 1>have you seen any like specifically designed for people who

428
00:19:20.440 --> 00:19:21.519
<v Speaker 1>are like more technical?

429
00:19:22.000 --> 00:19:25.119
<v Speaker 2>Oh yeah, They even have like pretexts for that.

430
00:19:25.519 --> 00:19:25.839
<v Speaker 1>Okay.

431
00:19:26.359 --> 00:19:28.920
<v Speaker 2>One of them is called like get your Updates here,

432
00:19:29.559 --> 00:19:32.680
<v Speaker 2>where the social engineer pretends to be from like your

433
00:19:32.680 --> 00:19:35.920
<v Speaker 2>IT department, right yeah, and they're urging you to visit

434
00:19:35.960 --> 00:19:39.640
<v Speaker 2>a website to register your computer for automatic security.

435
00:19:39.240 --> 00:19:42.559
<v Speaker 1>Updates, which sounds like perfectly.

436
00:19:42.160 --> 00:19:44.240
<v Speaker 3>Legitimate, totally legitimate, Yeah.

437
00:19:44.160 --> 00:19:46.400
<v Speaker 1>Especially for people who are like you know, used to

438
00:19:46.920 --> 00:19:49.680
<v Speaker 1>like keeping their software up to date exactly. Yeah.

439
00:19:49.720 --> 00:19:52.440
<v Speaker 2>It plays on that trust and authority figures and that

440
00:19:52.839 --> 00:19:56.039
<v Speaker 2>desire to you know, stay protected. But of course the

441
00:19:56.039 --> 00:19:58.759
<v Speaker 2>website is a fake right, designed to steal your log

442
00:19:58.799 --> 00:20:00.559
<v Speaker 2>in credentials or install malware.

443
00:20:00.759 --> 00:20:05.359
<v Speaker 1>Right. Okay, so I guess, like you know, none of

444
00:20:05.440 --> 00:20:07.440
<v Speaker 1>us are like immune to this stuff.

445
00:20:07.559 --> 00:20:10.319
<v Speaker 2>No one's immune. No, we all have our vulnerability, right,

446
00:20:10.359 --> 00:20:11.920
<v Speaker 2>they're masters at finding them.

447
00:20:12.000 --> 00:20:15.759
<v Speaker 1>Okay, So let's move on from email to telephone attacks,

448
00:20:16.799 --> 00:20:19.279
<v Speaker 1>because I think a lot of people would be surprised

449
00:20:19.319 --> 00:20:20.880
<v Speaker 1>to know that this is still one of the most

450
00:20:20.880 --> 00:20:23.319
<v Speaker 1>common forms of social engineering.

451
00:20:23.440 --> 00:20:24.119
<v Speaker 3>Oh yeah.

452
00:20:24.160 --> 00:20:27.559
<v Speaker 1>You know it's like in this age of like, you know,

453
00:20:27.640 --> 00:20:30.799
<v Speaker 1>texting an email, you'd think phone calls would be like

454
00:20:30.920 --> 00:20:31.680
<v Speaker 1>less effective.

455
00:20:31.960 --> 00:20:32.720
<v Speaker 3>Yeah, but.

456
00:20:35.160 --> 00:20:37.519
<v Speaker 1>I don't know. There's something about that, like human voice.

457
00:20:37.319 --> 00:20:41.240
<v Speaker 2>Human voice, Yeah, that like real time interaction. It's very powerful, right,

458
00:20:41.400 --> 00:20:44.240
<v Speaker 2>and it allows them to really adapt to like how

459
00:20:44.240 --> 00:20:46.920
<v Speaker 2>you're responding right, right, and make it even more believable.

460
00:20:47.000 --> 00:20:49.400
<v Speaker 1>Okay, So what are what are some of the scenarios

461
00:20:50.160 --> 00:20:51.200
<v Speaker 1>that we should be aware of.

462
00:20:51.559 --> 00:20:55.400
<v Speaker 2>So one of the classic ones is the forgetful user,

463
00:20:56.000 --> 00:20:59.720
<v Speaker 2>where the social engineer calls like the help desk, right

464
00:21:00.359 --> 00:21:04.039
<v Speaker 2>and pretends to be a legitimate user who's forgotten their passwords.

465
00:21:04.039 --> 00:21:06.440
<v Speaker 1>Oh yeah, I could totally see that working. Oh yeah,

466
00:21:06.759 --> 00:21:09.440
<v Speaker 1>because I mean, like we all forget our passwords.

467
00:21:09.559 --> 00:21:12.359
<v Speaker 2>Happens all the time, and to make it even more believable,

468
00:21:12.559 --> 00:21:14.960
<v Speaker 2>they'll be like, oh, I have this urgent deadline, you know,

469
00:21:15.079 --> 00:21:17.119
<v Speaker 2>or like my boss is waiting on me to send

470
00:21:17.119 --> 00:21:19.279
<v Speaker 2>this five you know, Like they create that sense of

471
00:21:19.400 --> 00:21:22.200
<v Speaker 2>urgency to pressure the help desk person to reset their

472
00:21:22.240 --> 00:21:24.599
<v Speaker 2>password without the proper verification.

473
00:21:24.759 --> 00:21:27.000
<v Speaker 1>Oh yeah, they're using their like you know, the help

474
00:21:27.039 --> 00:21:30.599
<v Speaker 1>desk person's desire to be helpful.

475
00:21:30.359 --> 00:21:31.680
<v Speaker 3>And efficient exactly.

476
00:21:31.839 --> 00:21:36.119
<v Speaker 2>So that highlights the importance of good authentication protocols. Right,

477
00:21:36.160 --> 00:21:38.759
<v Speaker 2>you know, always verify even when it seems legitimate.

478
00:21:38.839 --> 00:21:41.720
<v Speaker 1>Right, always verify. Yeah, okay, So what about like what

479
00:21:41.839 --> 00:21:46.559
<v Speaker 1>other you know, phone tactics you know, should we be

480
00:21:46.880 --> 00:21:47.519
<v Speaker 1>like aware of?

481
00:21:48.079 --> 00:21:52.079
<v Speaker 2>Right? So there's one called a sleight of hand where

482
00:21:52.440 --> 00:21:55.799
<v Speaker 2>the social engineer pretends to be from like it again,

483
00:21:56.319 --> 00:21:58.880
<v Speaker 2>calls you and then asks you to visit a website

484
00:21:59.000 --> 00:22:02.400
<v Speaker 2>to register your comp you know, okay, yeah, like for

485
00:22:02.839 --> 00:22:05.279
<v Speaker 2>system upgrade or new security software.

486
00:22:05.480 --> 00:22:07.640
<v Speaker 1>Right. Sounds legit, totally legit.

487
00:22:07.720 --> 00:22:10.319
<v Speaker 2>Yeah, happens all the time, But of course the website

488
00:22:10.440 --> 00:22:13.359
<v Speaker 2>is a fake, right, and it's designed to steal your

489
00:22:13.400 --> 00:22:16.640
<v Speaker 2>loging credentials. And what's clever is that they never actually

490
00:22:16.680 --> 00:22:19.119
<v Speaker 2>ask for the password, right, Like they just ask you

491
00:22:19.160 --> 00:22:21.279
<v Speaker 2>to go to this website. It's very clever.

492
00:22:21.440 --> 00:22:24.960
<v Speaker 1>So they're kind of bypassing your defenses.

493
00:22:24.440 --> 00:22:27.359
<v Speaker 2>Totally because you're expecting them to ask for your password,

494
00:22:27.400 --> 00:22:28.359
<v Speaker 2>but they don't.

495
00:22:28.480 --> 00:22:31.160
<v Speaker 1>Right, Okay, okay, what about like financial stuff?

496
00:22:31.240 --> 00:22:35.240
<v Speaker 2>Oh yeah, financial foray. So this is where the social

497
00:22:35.279 --> 00:22:39.000
<v Speaker 2>engineer pretends to be like a bank rep calling to

498
00:22:39.200 --> 00:22:40.359
<v Speaker 2>verify information.

499
00:22:40.759 --> 00:22:42.440
<v Speaker 1>Oh yeah, I get those calls. Get those?

500
00:22:42.519 --> 00:22:42.680
<v Speaker 3>Yeah.

501
00:22:42.720 --> 00:22:45.759
<v Speaker 2>It's really tricky, right because they sound super official, and

502
00:22:46.079 --> 00:22:49.759
<v Speaker 2>they often will have specific details about your account. They

503
00:22:49.839 --> 00:22:53.960
<v Speaker 2>might ask for your account number, your social even your

504
00:22:54.119 --> 00:22:58.119
<v Speaker 2>online banking log in credentials to you know, resolve a

505
00:22:58.119 --> 00:22:58.920
<v Speaker 2>minor issue.

506
00:22:59.039 --> 00:23:02.359
<v Speaker 1>Right. It's so hard to tell those from a legitimate call.

507
00:23:02.319 --> 00:23:02.680
<v Speaker 3>It is.

508
00:23:03.200 --> 00:23:06.720
<v Speaker 2>So the best advice is to never give out sensitive

509
00:23:06.759 --> 00:23:10.480
<v Speaker 2>information over the phone unless you initiated the call. Right.

510
00:23:10.640 --> 00:23:12.920
<v Speaker 2>If you get a call that seems suspicious, just hang

511
00:23:13.000 --> 00:23:16.000
<v Speaker 2>up right, call back using the number, the official number

512
00:23:16.039 --> 00:23:18.839
<v Speaker 2>you know, exlisted on your statement, your website, whatever.

513
00:23:19.000 --> 00:23:23.480
<v Speaker 1>Good rule with them, Always verify, always verify. Yeah yeah, okay,

514
00:23:23.640 --> 00:23:25.920
<v Speaker 1>so what about those like you know, we all get

515
00:23:25.960 --> 00:23:28.839
<v Speaker 1>those like robo calls, right, I feel like they're coming

516
00:23:28.839 --> 00:23:29.720
<v Speaker 1>more and more these days.

517
00:23:29.799 --> 00:23:32.000
<v Speaker 2>Oh yeah, yeah, and they're using those too. The book

518
00:23:32.079 --> 00:23:35.319
<v Speaker 2>calls it attack of the Phones, where they use like

519
00:23:35.400 --> 00:23:38.680
<v Speaker 2>a text to speech a program to create like this

520
00:23:38.839 --> 00:23:42.279
<v Speaker 2>fake automated call. Oh yeah, pretending to be from the IRS,

521
00:23:42.359 --> 00:23:44.000
<v Speaker 2>a government agency.

522
00:23:43.759 --> 00:23:46.759
<v Speaker 1>Yeah. They're usually warning you about some kind of legal

523
00:23:46.799 --> 00:23:50.319
<v Speaker 1>action or like unpaid taxes, totally. Yeah, and then they

524
00:23:50.319 --> 00:23:53.200
<v Speaker 1>want you to like enter personal information exactly.

525
00:23:53.319 --> 00:23:57.000
<v Speaker 2>Yeah, and they're exploiting again our fear of authority, our

526
00:23:57.039 --> 00:24:01.920
<v Speaker 2>tendency to trust automated systems. The call might even instruct

527
00:24:01.960 --> 00:24:05.319
<v Speaker 2>you to like enter your Social Security number right for verification,

528
00:24:05.480 --> 00:24:07.759
<v Speaker 2>and then they can capture that. They use something called

529
00:24:07.759 --> 00:24:09.200
<v Speaker 2>a DTMF decoder.

530
00:24:09.319 --> 00:24:12.519
<v Speaker 1>Oh, a DTMF decoder. What is that? That sounds fancy.

531
00:24:12.559 --> 00:24:17.319
<v Speaker 2>It sounds super fancy, right. So DTMF stands for dual

532
00:24:17.359 --> 00:24:21.759
<v Speaker 2>tone multi frequency signaling. It's basically the technology that allows

533
00:24:21.839 --> 00:24:25.759
<v Speaker 2>you to like press the keys on your phone, you know, Okay, yeah,

534
00:24:25.759 --> 00:24:27.200
<v Speaker 2>like one for sales or whatever.

535
00:24:27.359 --> 00:24:29.799
<v Speaker 1>I've never thought about how that actually works, but yeah.

536
00:24:29.680 --> 00:24:31.839
<v Speaker 2>Yeah, so they can use that. Oh, they have this

537
00:24:31.920 --> 00:24:33.240
<v Speaker 2>decoder that can capture that.

538
00:24:33.519 --> 00:24:36.799
<v Speaker 1>So it's like they're even though it seems automated, they're

539
00:24:36.799 --> 00:24:38.000
<v Speaker 1>actually listening.

540
00:24:37.640 --> 00:24:38.440
<v Speaker 3>In they are.

541
00:24:38.720 --> 00:24:44.079
<v Speaker 2>Yeah, essentially, it's scary, so be cautious about providing any

542
00:24:44.119 --> 00:24:47.480
<v Speaker 2>information over the phone, even if it seems like it's automated.

543
00:24:47.880 --> 00:24:50.759
<v Speaker 1>Right. Okay, so we've covered some pretty sophisticated stuff like

544
00:24:50.799 --> 00:24:54.799
<v Speaker 1>you know, email and telephone attacks. What about like, what

545
00:24:54.880 --> 00:24:56.759
<v Speaker 1>other tricks do they have up their sleeves?

546
00:24:57.160 --> 00:25:01.279
<v Speaker 2>Okay, So there's another tactic that's like surprisingly simple, but

547
00:25:01.279 --> 00:25:05.359
<v Speaker 2>it's still very effective, called baiting. It preys on our

548
00:25:05.400 --> 00:25:07.799
<v Speaker 2>curiosity and our love of free stuff.

549
00:25:08.039 --> 00:25:09.759
<v Speaker 1>Okay, I like free stuff, tell me more.

550
00:25:10.119 --> 00:25:14.839
<v Speaker 2>So it's about leaving like infected media like USB drives

551
00:25:14.960 --> 00:25:19.039
<v Speaker 2>or CDs okay, around in places where, like you know,

552
00:25:19.319 --> 00:25:22.039
<v Speaker 2>the target is likely to find them, right, and the

553
00:25:22.079 --> 00:25:26.240
<v Speaker 2>media is often labeled with something enticing like payroll or

554
00:25:26.279 --> 00:25:27.319
<v Speaker 2>private picks you.

555
00:25:27.279 --> 00:25:29.319
<v Speaker 1>Know, right, it's like, I don't know, it's like finding

556
00:25:29.319 --> 00:25:31.400
<v Speaker 1>a twenty dollars bill on the sidewalk. It is, you know,

557
00:25:31.440 --> 00:25:33.400
<v Speaker 1>you probably shouldn't pick it up, but it's so hard to.

558
00:25:33.359 --> 00:25:36.640
<v Speaker 2>Resist exactly, And the book calls this like the oldie

559
00:25:36.640 --> 00:25:39.839
<v Speaker 2>but a goodie. Right. It's crazy how effective it still is.

560
00:25:40.000 --> 00:25:43.160
<v Speaker 1>Yeah, so give me some give me some real world examples,

561
00:25:43.160 --> 00:25:44.599
<v Speaker 1>like how does this actually play out?

562
00:25:44.759 --> 00:25:48.839
<v Speaker 2>Okay? So there's like the Blazing Fast interwebs where they

563
00:25:49.039 --> 00:25:51.880
<v Speaker 2>mail you a USB drive disguised as like an Internet

564
00:25:51.920 --> 00:25:52.559
<v Speaker 2>speed booster.

565
00:25:52.759 --> 00:25:53.039
<v Speaker 1>Yeah.

566
00:25:53.079 --> 00:25:53.720
<v Speaker 3>Oh, I would.

567
00:25:53.599 --> 00:25:56.319
<v Speaker 2>Totally fall for that. Who doesn't want faster Internet?

568
00:25:56.519 --> 00:26:00.880
<v Speaker 1>Exactly? It plays on that desire for like instant gratification,

569
00:26:01.160 --> 00:26:04.039
<v Speaker 1>right right, right? Are willing not to try new technologies,

570
00:26:04.119 --> 00:26:07.359
<v Speaker 1>especially if they're free, especially if they're free. Yeah, but

571
00:26:07.519 --> 00:26:10.200
<v Speaker 1>in reality it's just a sneaky way to get you

572
00:26:10.279 --> 00:26:13.920
<v Speaker 1>to install malware, right okay? Okay. And then there's the

573
00:26:14.720 --> 00:26:18.480
<v Speaker 1>Save Big Money where they mail you a USB drive

574
00:26:18.480 --> 00:26:21.960
<v Speaker 1>that appears to contain a coupon book. Ooh, I love

575
00:26:22.319 --> 00:26:27.400
<v Speaker 1>everyone loves coupon's huge discounts. Yeah, popular stores. And then

576
00:26:27.640 --> 00:26:29.039
<v Speaker 1>you know, as soon as you plug in the drive,

577
00:26:29.160 --> 00:26:30.160
<v Speaker 1>bam malware.

578
00:26:30.319 --> 00:26:30.720
<v Speaker 3>Okay.

579
00:26:30.839 --> 00:26:33.640
<v Speaker 2>So if something seems too good to be true, it probably.

580
00:26:33.240 --> 00:26:36.400
<v Speaker 1>Is exactly yeah. And then they even like tailor it

581
00:26:36.440 --> 00:26:37.759
<v Speaker 1>to specific interests.

582
00:26:38.000 --> 00:26:38.440
<v Speaker 3>Oh okay.

583
00:26:38.640 --> 00:26:41.559
<v Speaker 1>For car enthusiasts, you know, they have the Recalling all Cars,

584
00:26:41.960 --> 00:26:45.119
<v Speaker 1>where they mail you a USB drive claiming it contains

585
00:26:45.519 --> 00:26:49.640
<v Speaker 1>like important information about a recall for your specific make

586
00:26:49.720 --> 00:26:50.440
<v Speaker 1>and model of car.

587
00:26:50.640 --> 00:26:53.880
<v Speaker 2>Oh yeah, I mean a car recall is like a

588
00:26:53.880 --> 00:26:54.359
<v Speaker 2>big deal.

589
00:26:54.559 --> 00:26:57.519
<v Speaker 1>It's a big deal, right, like both safety and like

590
00:26:57.599 --> 00:26:58.880
<v Speaker 1>you know, could cost you a lot of.

591
00:26:58.880 --> 00:27:03.799
<v Speaker 2>Money, totally praying on that desire to keep our vehicles

592
00:27:03.839 --> 00:27:05.519
<v Speaker 2>running smoothly and to be safe.

593
00:27:05.799 --> 00:27:08.799
<v Speaker 1>Right, so again like you know, using our own anxieties

594
00:27:08.799 --> 00:27:09.759
<v Speaker 1>against us totally.

595
00:27:10.599 --> 00:27:14.359
<v Speaker 2>And then finally the bank security software. So they mail

596
00:27:14.440 --> 00:27:18.680
<v Speaker 2>you a USB drive claiming it contains security software, right

597
00:27:18.680 --> 00:27:20.920
<v Speaker 2>to protect your computer and your bank account.

598
00:27:21.000 --> 00:27:23.960
<v Speaker 1>Oh yeah, that makes sense. Like with all the data

599
00:27:23.960 --> 00:27:27.640
<v Speaker 1>breaches and identity theft happening these days, you know, Oh yeah,

600
00:27:27.799 --> 00:27:30.880
<v Speaker 1>people are very concerned about their online security.

601
00:27:30.440 --> 00:27:34.759
<v Speaker 2>Absolutely, so they combine the appeal of free security software

602
00:27:34.799 --> 00:27:37.759
<v Speaker 2>with that fear of financial fraud. Right, and to make

603
00:27:37.759 --> 00:27:41.799
<v Speaker 2>it even more urgent, they might even reference some suspicious activity.

604
00:27:41.519 --> 00:27:42.960
<v Speaker 3>Right right on your account.

605
00:27:43.079 --> 00:27:46.599
<v Speaker 1>Okay. So it's all about playing on our emotions, our fears,

606
00:27:46.599 --> 00:27:47.839
<v Speaker 1>and our desires.

607
00:27:48.079 --> 00:27:48.400
<v Speaker 3>It is.

608
00:27:48.519 --> 00:27:51.720
<v Speaker 2>Yeah. What's striking is that all these tactics they rely

609
00:27:51.839 --> 00:27:56.160
<v Speaker 2>on exploiting human nature. It's not about like brute force hacking.

610
00:27:56.240 --> 00:27:58.279
<v Speaker 2>It's about manipulating our psychology.

611
00:27:58.680 --> 00:28:01.400
<v Speaker 1>Right. It really makes you like think twice about who

612
00:28:01.400 --> 00:28:01.880
<v Speaker 1>you trust.

613
00:28:02.000 --> 00:28:02.440
<v Speaker 3>It does.

614
00:28:02.680 --> 00:28:05.119
<v Speaker 1>Yeah, it's scary and how easily. We can be deceived

615
00:28:05.359 --> 00:28:08.559
<v Speaker 1>very easily, right, So it really brings us back to

616
00:28:09.119 --> 00:28:11.720
<v Speaker 1>like the core message of this whole deep dive, right,

617
00:28:12.160 --> 00:28:12.960
<v Speaker 1>like knowledge is.

618
00:28:12.920 --> 00:28:13.759
<v Speaker 3>Power, totally.

619
00:28:14.079 --> 00:28:16.759
<v Speaker 2>Yeah, the more you understand about these tactics, the better

620
00:28:16.799 --> 00:28:17.839
<v Speaker 2>you can protect yourself.

621
00:28:18.079 --> 00:28:20.640
<v Speaker 1>So it's not about living in fear. No, it's about

622
00:28:20.720 --> 00:28:23.319
<v Speaker 1>being like you know, informed and.

623
00:28:23.240 --> 00:28:26.680
<v Speaker 2>Aware, being aware exactly, and that's like your first line

624
00:28:26.720 --> 00:28:29.079
<v Speaker 2>of defense, you know. Just start paying attention to how

625
00:28:29.119 --> 00:28:30.519
<v Speaker 2>people try to influence you.

626
00:28:30.440 --> 00:28:31.279
<v Speaker 3>In everyday life.

627
00:28:31.359 --> 00:28:34.599
<v Speaker 2>I know, right, I guarantee you'll start to see it everywhere.

628
00:28:34.319 --> 00:28:37.559
<v Speaker 1>I'm already noticing it, and it's like a little unsettling.

629
00:28:37.079 --> 00:28:38.440
<v Speaker 3>Honestly, it is unsettling.

630
00:28:38.799 --> 00:28:41.119
<v Speaker 2>Yeah, but you're already way ahead of the game, right right,

631
00:28:41.200 --> 00:28:43.759
<v Speaker 2>because you're aware of it. You're less likely to fall

632
00:28:43.799 --> 00:28:46.240
<v Speaker 2>for those traps because you know what to look for.

633
00:28:46.599 --> 00:28:49.440
<v Speaker 1>Okay, So I guess to kind of like, you know,

634
00:28:49.480 --> 00:28:53.359
<v Speaker 1>wrap up this whole conversation social engineering. It's really all

635
00:28:53.400 --> 00:28:58.599
<v Speaker 1>about exploiting the human element, right, our trust, our helpfulness,

636
00:28:59.119 --> 00:29:02.880
<v Speaker 1>even our desired to be liked, and it uses psychology

637
00:29:03.000 --> 00:29:05.319
<v Speaker 1>and trickery to get us to do things that we

638
00:29:05.359 --> 00:29:06.160
<v Speaker 1>wouldn't normally do.

639
00:29:06.359 --> 00:29:08.880
<v Speaker 2>Totally right, And the best way to protect yourself is

640
00:29:08.920 --> 00:29:13.200
<v Speaker 2>to stay informed, be skeptical, never be afraid to question authority.

641
00:29:13.400 --> 00:29:17.000
<v Speaker 2>If something feels off, it probably is. Trust your gut.

642
00:29:17.359 --> 00:29:17.880
<v Speaker 1>I love that.

643
00:29:18.240 --> 00:29:22.119
<v Speaker 2>Trust your gut, verify information. Yeah, and remember that no

644
00:29:22.160 --> 00:29:25.119
<v Speaker 2>one has the right to pressure you into giving up

645
00:29:25.160 --> 00:29:26.559
<v Speaker 2>sensitive information.

646
00:29:26.279 --> 00:29:28.240
<v Speaker 1>Right exactly. And I think you know the trust your

647
00:29:28.279 --> 00:29:30.920
<v Speaker 1>gut part, it's so important. It's huge, right because we

648
00:29:31.000 --> 00:29:34.839
<v Speaker 1>often like have that feeling, you know, like something's not right,

649
00:29:35.240 --> 00:29:36.799
<v Speaker 1>but we just kind of ignore it because we want

650
00:29:36.799 --> 00:29:38.359
<v Speaker 1>to want to seem rude or paranom you.

651
00:29:38.359 --> 00:29:41.960
<v Speaker 2>Feel like we're overreacting or whatever. But it's much better

652
00:29:42.000 --> 00:29:44.720
<v Speaker 2>to be cautious than to become a victim. You know.

653
00:29:44.839 --> 00:29:49.079
<v Speaker 2>It's about finding that balance between being open and trusting

654
00:29:49.519 --> 00:29:51.160
<v Speaker 2>but also discerning and aware.

655
00:29:51.559 --> 00:29:55.400
<v Speaker 1>Yeah, it's tricky. It is tricky, and you know, it's

656
00:29:55.480 --> 00:29:58.920
<v Speaker 1>not just about protecting ourselves personally, but also our organizations

657
00:29:59.200 --> 00:30:02.680
<v Speaker 1>absolutely and their communities. Like this stuff can have like

658
00:30:03.119 --> 00:30:05.160
<v Speaker 1>far reaching consequences, oh yeah.

659
00:30:05.039 --> 00:30:09.119
<v Speaker 2>Data breaches, financial losses, reputational damage, like it can get

660
00:30:09.240 --> 00:30:09.839
<v Speaker 2>really bad.

661
00:30:10.039 --> 00:30:13.880
<v Speaker 1>Right, Okay, So to our listeners out there, stay vigilant,

662
00:30:13.960 --> 00:30:18.759
<v Speaker 1>stay informed, stay informed, stay safe, stay safe and if

663
00:30:18.799 --> 00:30:22.200
<v Speaker 1>you really want to like dive deep into this whole

664
00:30:22.200 --> 00:30:26.440
<v Speaker 1>world of social engineering, definitely check out the Social Engineer's Playbook. Yeah.

665
00:30:26.519 --> 00:30:29.839
<v Speaker 2>The book is really interesting. It lays everything out very clearly. Yeah,

666
00:30:30.039 --> 00:30:32.680
<v Speaker 2>and I think even if you just implement like a

667
00:30:32.680 --> 00:30:35.119
<v Speaker 2>few of the tips we've talked about, you'll be much

668
00:30:35.160 --> 00:30:37.400
<v Speaker 2>better off, right exactly, Yes, significantly.

669
00:30:37.960 --> 00:30:40.720
<v Speaker 1>And a if you've ever encountered any particularly like you know,

670
00:30:41.119 --> 00:30:44.640
<v Speaker 1>clever or outrageous social engineering attempts, we want to hear

671
00:30:44.680 --> 00:30:45.079
<v Speaker 1>about them.

672
00:30:45.400 --> 00:30:47.559
<v Speaker 2>Oh yeah, share your stories.

673
00:30:47.160 --> 00:30:49.799
<v Speaker 1>Share your stories, hit us up on social media.

674
00:30:49.960 --> 00:30:51.720
<v Speaker 3>Yeah, we want to hear them, right.

675
00:30:51.759 --> 00:30:53.960
<v Speaker 1>Because I mean, I think you know, the best way

676
00:30:53.960 --> 00:30:56.480
<v Speaker 1>to learn is from you know, shared experiences.

677
00:30:56.039 --> 00:30:58.279
<v Speaker 2>Right, Absolutely, learn from each other's mistakes.

678
00:30:58.400 --> 00:31:02.519
<v Speaker 1>Right. So until next time, I'm stay curious, stay skeptical,

679
00:31:03.039 --> 00:31:05.759
<v Speaker 1>and stay safe out there in the digital wild West.

680
00:31:06.119 --> 00:31:09.000
<v Speaker 2>And remember knowledge is power.

681
00:31:09.400 --> 00:31:13.440
<v Speaker 1>Yes, thanks for joining us for another deep dive. We'll

682
00:31:13.440 --> 00:31:19.240
<v Speaker 1>see you next time. Forewarned is forearmed, right exactly. So

683
00:31:19.279 --> 00:31:21.799
<v Speaker 1>the more we know about these tactics, the better we

684
00:31:21.839 --> 00:31:22.680
<v Speaker 1>can protect ourselves.

685
00:31:22.720 --> 00:31:26.759
<v Speaker 2>Absolutely, awareness is your first line of defense. And just

686
00:31:26.799 --> 00:31:30.960
<v Speaker 2>start paying attention to how people try to influence you

687
00:31:31.000 --> 00:31:34.720
<v Speaker 2>in everyday life. I know, online, offline, everywhere. I guarantee

688
00:31:34.759 --> 00:31:36.720
<v Speaker 2>you'll start to see it everywhere once you start looking

689
00:31:36.720 --> 00:31:37.000
<v Speaker 2>for it.

690
00:31:37.079 --> 00:31:39.319
<v Speaker 1>Oh yeah, I'm already noticing it. Yes, And it is

691
00:31:39.319 --> 00:31:40.799
<v Speaker 1>a little it's a little unsettling.

692
00:31:40.960 --> 00:31:43.039
<v Speaker 2>It is unsettling. But the good news is you're already

693
00:31:43.039 --> 00:31:45.319
<v Speaker 2>ahead of the game because you're aware of it, right,

694
00:31:45.519 --> 00:31:47.759
<v Speaker 2>So you're less likely to fall for those traps because

695
00:31:47.799 --> 00:31:49.279
<v Speaker 2>you know what to look for, right.

696
00:31:49.400 --> 00:31:50.200
<v Speaker 1>So it's a good thing.

697
00:31:50.839 --> 00:31:51.240
<v Speaker 3>Okay.

698
00:31:51.319 --> 00:31:54.400
<v Speaker 2>So to kind of like wrap up this whole conversation,

699
00:31:55.640 --> 00:31:59.000
<v Speaker 2>social engineering, I mean, it's really all about exploiting the

700
00:31:59.079 --> 00:32:02.400
<v Speaker 2>human element, our trust, our helpfulness, even our desire to

701
00:32:02.440 --> 00:32:06.880
<v Speaker 2>be liked. Yeah, and it uses psychology and trickery to

702
00:32:07.000 --> 00:32:09.799
<v Speaker 2>get us to do things that we would normally do.

703
00:32:10.119 --> 00:32:12.799
<v Speaker 2>Totally and the best way to protect ourselves. I mean,

704
00:32:12.960 --> 00:32:16.039
<v Speaker 2>just to reiterate what we've been talking about, stay informed,

705
00:32:16.119 --> 00:32:19.839
<v Speaker 2>be skeptical, never be afraid to question authority.

706
00:32:20.039 --> 00:32:21.880
<v Speaker 1>Absolutely question everything.

707
00:32:22.039 --> 00:32:26.240
<v Speaker 2>Right, if something feels off, it probably is. Trust your gut,

708
00:32:27.039 --> 00:32:31.039
<v Speaker 2>verify information, and remember that no one has the right

709
00:32:31.160 --> 00:32:34.480
<v Speaker 2>to pressure you into giving up sensitive information or access.

710
00:32:34.559 --> 00:32:35.799
<v Speaker 1>Couldn't this set it better myself?

711
00:32:35.960 --> 00:32:37.200
<v Speaker 2>Yeah?

712
00:32:37.240 --> 00:32:38.119
<v Speaker 3>I love that advice.

713
00:32:38.279 --> 00:32:41.319
<v Speaker 2>Trust your gut. It's so simple, it's so sick, but

714
00:32:41.359 --> 00:32:44.680
<v Speaker 2>it's so important, right, because we often have that feeling like, hmmm,

715
00:32:44.880 --> 00:32:47.039
<v Speaker 2>something's not right here, but we just kind of ignore

716
00:32:47.079 --> 00:32:49.839
<v Speaker 2>it because we don't want to seem rude or paranoid exactly.

717
00:32:49.960 --> 00:32:52.000
<v Speaker 1>Yeah, I think we're overreacting or whatever.

718
00:32:52.519 --> 00:32:55.000
<v Speaker 2>But it's much better to be cautious than to become

719
00:32:55.000 --> 00:32:55.440
<v Speaker 2>a victim.

720
00:32:55.519 --> 00:32:55.759
<v Speaker 3>Right.

721
00:32:55.839 --> 00:33:00.000
<v Speaker 2>It's about finding that balance between you know, being open

722
00:33:00.079 --> 00:33:03.839
<v Speaker 2>and trusting, but also discerning and aware.

723
00:33:03.759 --> 00:33:06.279
<v Speaker 1>Right, discerning in a way. Yeah, it's a tricky balance.

724
00:33:06.319 --> 00:33:06.920
<v Speaker 3>It is tricky.

725
00:33:07.079 --> 00:33:11.720
<v Speaker 1>Yeah. And you know, it's not just about protecting ourselves personally, no, right, Like,

726
00:33:11.839 --> 00:33:15.519
<v Speaker 1>it's about protecting our organizations, our communities absolutely. I mean

727
00:33:15.519 --> 00:33:18.160
<v Speaker 1>this stuff can have like really far reaching.

728
00:33:17.880 --> 00:33:21.720
<v Speaker 2>Consequences, data breaches, financial losses, reputational damage.

729
00:33:21.720 --> 00:33:22.920
<v Speaker 3>I mean it can be really bad.

730
00:33:23.039 --> 00:33:27.640
<v Speaker 1>Right. Okay, So to our listeners out there, stay vigilant,

731
00:33:28.000 --> 00:33:31.640
<v Speaker 1>stay informed, stay safe, stay safe, and if you want

732
00:33:31.640 --> 00:33:33.920
<v Speaker 1>to like really dive deep into this whole world of

733
00:33:33.960 --> 00:33:37.680
<v Speaker 1>social engineering, definitely check out the Social Engineer's Playbook.

734
00:33:37.720 --> 00:33:38.480
<v Speaker 2>It's a great book.

735
00:33:38.559 --> 00:33:40.720
<v Speaker 1>Yeah. We'll put a link in the show notes along

736
00:33:40.720 --> 00:33:42.960
<v Speaker 1>with some of the other resources that we mentioned. And hey,

737
00:33:43.160 --> 00:33:46.519
<v Speaker 1>if you have ever encountered any particularly you know, clever

738
00:33:46.720 --> 00:33:50.359
<v Speaker 1>or outrageous social engineering attempts, we want to hear about them.

739
00:33:50.440 --> 00:33:53.960
<v Speaker 1>Share them, share them. Yeah, hit us up on social media.

740
00:33:54.000 --> 00:33:56.039
<v Speaker 3>We love we love those stories because.

741
00:33:55.799 --> 00:33:57.839
<v Speaker 1>I think sometimes, you know, the best way to learn

742
00:33:57.920 --> 00:33:59.680
<v Speaker 1>is from shared experiences.

743
00:33:59.160 --> 00:34:02.279
<v Speaker 2>Right, Yeah, absolutely learn from each other's mistakes.

744
00:34:02.559 --> 00:34:06.599
<v Speaker 1>So until next time, stay curious, stay skeptical, and stay

745
00:34:06.640 --> 00:34:08.840
<v Speaker 1>safe out there in the digital wild West.

746
00:34:08.960 --> 00:34:11.719
<v Speaker 2>And remember knowledge is power.

747
00:34:12.719 --> 00:34:15.199
<v Speaker 1>Thanks for joining us for another deep dive. We'll see

748
00:34:15.239 --> 00:34:15.719
<v Speaker 1>you next time.
