Newsflash: Common Sense Illuminates Friendly Fish for Phishers

June 16, 2023

Vea4_thumb_thumb_thumb_thumb_thumb_t[1]Note: This essay is the work of a real and still-alive dinobaby. No smart software involved, just a dumb humanoid.

Here’s a quick insider threat and phishing victim test: [a] Are you really friendly, fraternity or sorority social officer gregarious humanoid? [b] Are you a person who says “Yes” to almost any suggestion a friend or stranger makes to you? [c] Are you curious about emails offering big bucks, free prizes, or great deals on avocado slicers?

If you resonated with a, b, or c, researchers have some news for you.

Younger, More Extroverted, and More Agreeable Individuals Are More Vulnerable to Email Phishing Scams” reports:

… the older you are, the less susceptible you are to phishing scams. In addition, highly extroverted and agreeable people are more susceptible to this style of cyber attack. This research holds the potential to provide valuable guidance for future cybersecurity training, considering the specific knowledge and skills required to address age and personality differences.

The research summary continues:

The results of the current study support the idea that people with poor self-control and impulsive tendencies are more likely to misclassify phishing emails as legitimate. Interestingly, impulsive individuals also tend to be less confident in their classifications, suggesting they are somewhat aware of their vulnerability.

It is good to be an old, irascible, skeptical dinobaby after all.

Stephen E Arnold, June 16, 2023

Is This for Interns, Contractors, and Others Whom You Trust?

June 14, 2023

Not too far from where my office is located, an esteemed health care institution is in its second month of a slight glitch. The word in Harrod’s Creek is that security methods at use at a major hospital were — how shall I frame this — a bit like the 2022-2023 University of Kentucky’s’ basketball team’s defense. In Harrod’s Creek lingo, this statement would translate to standard English as “them ‘Cats did truly suck.”

6 12 temp worker

A young temporary worker looks at her boss. She says, “Yes, I plugged a USB drive into this computer because I need to move your PowerPoint to a different machine to complete the presentation.” The boss says, “Okay, you can use the desktop in my office. I have to go to a cyber security meeting. See you after lunch. Text me if you need a password to something.” The illustration for this hypothetical conversation emerged from the fountain of innovation known as MidJourney.

The chatter about assorted Federal agencies’ cyber personnel meeting with the institution’s own cyber experts are flitting around. When multiple Federal entities park their unobtrusive and sometimes large black SUVs close to the main entrance, someone is likely to notice.

This short blog post, however, is not about the lame duck cyber security at the health care facility. (I would add an anecdote about an experience I had in 2022. I showed up for a check up at a unit of the health care facility. Upon arriving, I pronounced my date of birth and my name. The professional on duty said, “We have an appointment for your wife and we have her medical records.” Well, that was a trivial administrative error: Wrong patient, confidential information shipped to another facility, and zero idea how that could happen. I made the appointment myself and provided the required information. That’s a great computer systems and super duper security in my book.)

The question at hand, however, is: “How can a profitable, marketing oriented, big time in their mind health care outfit, suffer a catastrophic security breach?”

I shall point you to one possible pathway: Temporary workers, interns, and contractors. I will not mention other types of insiders.

Please, point your browser to and read about the USB Rubber Ducky. With a starting price of $80US, this USB stick has some functions which can accomplish some interesting actions. The marketing collateral explains:

Computers trust humans. Humans use keyboards. Hence the universal spec — HID, or Human Interface Device. A keyboard presents itself as a HID, and in turn it’s inherently trusted as human by the computer. The USB Rubber Ducky — which looks like an innocent flash drive to humans — abuses this trust to deliver powerful payloads, injecting keystrokes at superhuman speeds.

With the USB Rubby Ducky, one can:

  • Install backdoors
  • Covertly exfiltrate documents
  • Capture credential
  • Execute compound actions.

Plus, if there is a USB port, the Rubber Ducky will work.

I mention this device because it may not too difficult for a bad actor to find ways into certain types of super duper cyber secure networks. Plus temporary workers and even interns welcome a coffee in an organization’s cafeteria or a nearby coffee shop. Kick in a donut and a smile and someone may plug the drive in for free!

Stephen E Arnold, June 14, 2023

Microsoft: Just a Minor Thing

June 6, 2023

Several years ago, I was asked to be a technical advisor to a UK group focused on improper actions directed toward children. Since then, I have paid some attention to the information about young people that some online services collect. One of the more troubling facets of improper actions intended to compromise the privacy, security, and possibly the safety of minors is the role data aggregators play. Whether gathering information from “harmless” apps favored by young people to surreptitious collection and cross correlation of young users’ online travels, these often surreptitious actions of people and their systems trouble me.

The “anything goes” approach of some organizations is often masked by public statements and the use of words like “trust” when explaining how information “hoovering” operations are set up, implemented, and used to generate revenue or other outcomes. I am not comfortable identifying some of these, however.

6 6 good deal

A regulator and a big company representative talking about a satisfactory resolution to the regrettable collection of kiddie data. Both appear to be satisfied with another job well done. The image was generated by the MidJourney smart software.

Instead, let me direct your attention to the BBC report “Microsoft to Pay $20m for Child Privacy Violations.” The write up states as “real news”:
Microsoft will pay $20m (£16m) to US federal regulators after it was found to have illegally collected

data on children who had started Xbox accounts.

The write up states:

From 2015 to 2020 Microsoft retained data “sometimes for years” from the account set up, even when a parent failed to complete the process …The company also failed to inform parents about all the data it was collecting, including the user’s profile picture and that data was being distributed to third parties.

Will the leader in smart software and clever marketing have an explanation? Of course. That’s what advisory firms and lawyers help their clients deliver; for example:

“Regrettably, we did not meet customer expectations and are committed to complying with the order to continue improving upon our safety measures,” Microsoft’s Dave McCarthy, CVP of Xbox Player Services, wrote in an Xbox blog post. “We believe that we can and should do more, and we’ll remain steadfast in our commitment to safety, privacy, and security for our community.”

Sounds good.

From my point of view, something is out of alignment. Perhaps it is my old-fashioned idea that young people’s online activities require a more thoughtful approach by large companies, data aggregators, and click capturing systems. The thought, it seems, is directed at finding ways to take advantage of weak regulation, inattentive parents and guardians, and often-uninformed young people.

Like other ethical black holes in certain organizations, surfing for fun or money on children seems inappropriate. Does $20 million have an impact on a giant company? Nope. The ethical and moral foundation of decision making is enabling these data collection activities. And $20 million causes little or no pain. Therefore, why not continue these practices and do a better job of keeping the procedures secret?

Pragmatism is the name of the game it seems. And kiddie data? Fair game to some adrift in an ethical swamp. Just a minor thing.

Stephen E Arnold, June 6, 2023

Need a Guide to Destroying Social Cohesion: Chinese Academics Have One for You

May 25, 2023

The TikTok service is one that has kicked the Google in its sensitive bits. The “algorithm” befuddles both European and US “me too” innovators. The ability of short, crunchy videos has caused restaurant chefs to craft food for TikTok influencers who record meals. Chefs!

What other magical powers can a service like TikTok have? That’s a good question, and it is one that the Chinese academics have answered. Navigate to “Weak Ties Strengthen Anger Contagion in Social Media.” The main idea of the research is to validate a simple assertion: Can social media (think TikTok, for example) take a flame thrower to social ties? The answer is, “Sure can.” Will a social structure catch fire and collapse? “Sure can.”

5 19 social structure on fire

A frail structure is set on fire by a stream of social media consumed by a teen working in his parents’ garden shed. MidJourney would not accept the query a person using a laptop setting his friends’ homes on fire. Thanks, Aunt MidJourney.

The write up states:

Increasing evidence suggests that, similar to face-to-face communications, human emotions also spread in online social media.

Okay, a post or TikTok video sparks emotion.

So what?

…we find that anger travels easily along weaker ties than joy, meaning that it can infiltrate different communities and break free of local traps because strangers share such content more often. Through a simple diffusion model, we reveal that weaker ties speed up anger by applying both propagation velocity and coverage metrics.

The authors note:

…we offer solid evidence that anger spreads faster and wider than joy in social media because it disseminates preferentially through weak ties. Our findings shed light on both personal anger management and in understanding collective behavior.

I wonder if any psychological operations professionals in China or another country with a desire to reduce the efficacy of the American democratic “experiment” will find the research interesting?

Stephen  E Arnold, May 25, 2023

Those Mobile Phones Are Something, Are They Not?

May 23, 2023

Apple, Google, Samsung, and a covey of Chinese mobile phone innovators have improved modern life. Imagine. People have a phone. No sharing  one telephone in a fraternity house, a cheap flat, or at an airport, just call, text, vlog, or swipe.

Are their downsides? For a quarter century the American Psychological Association was not sure. Now an outfit called Sapien Labs provides additional information about mobile phone usage.

For me, there were several highlights in the article “Kids Who Get Smartphones Earlier Become Adults With Worse Mental Health.”

First, the idea that young people who tap, swipe, and suck down digital information are unlikely to emulate Jonathan Edwards, Mother Teresa, or the ambiguous St. Thomas of Aquinas. The article states:

the younger the age of getting the first smartphone, the worse the mental health that the young adult reports today.

Obvious to some, but a scientific study adds more credence to the parent who says no to a child’s demand for a mobile phone or tablet.

Second, women (females) are more affected by the mobile phone. The study points out six categories of impact. Please, consult the article and the full study for the academic details. Again. No big surprise, but I wouldn’t ignore the fact that in some male cohorts, suicides are increasing. Regardless of gender, mobile phones appear to nudge some into wackiness or the ultimate solution to having friends make fun of one’s sneakers.

Third, I was surprised to learn that some young people get phones when they are five years old. I have seen very young children poking at an iPad in a restaurant or playing games on the parental unit’s mobile phones in an airport. I did not know the child had a phone to call his own. Good marketing by Apple, Google, Samsung, and Chinese outfits!

The study identifies a number of implications. Again, I am okay with those identified, but the cyber crime crowd was not discussed. My own perception is that mobile devices are the catalyst for a wide range of cyber crime. Once again, the unintended consequences of a mobile device have the capacity to enable some societal modifications that may be impossible to remediate.

Again: Nice work!

Stephen E Arnold, May 23, 2023

Is It Lights Out on the Information Superhighway?

April 26, 2023

We just completed a lecture about the shadow web. This is our way of describing a number of technologies specifically designed to prevent law enforcement, tax authorities, and other entities charged with enforcing applicable laws in the dark.

Among the tools available are roulette services. These can be applied to domain proxies so it is very difficult to figure out where a particular service is at a particular point in time. Tor has uttered noises about supporting the Mullvad browser and baking in a virtual private network. But there are other VPNs available, and one of the largest infrastructure service providers is under what appears to be “new” ownership. Change may create a problem for some enforcement entities. Other developers work overtime to provide services primarily to those who want to deploy what we call “traditional Dark Web sites.” Some of these obfuscation software components are available on Microsoft’s GitHub.

I want to point to “Global Law Enforcement Coalition Urges Tech Companies to Rethink Encryption Plans That Put Children in Danger from Online Abusers.” The main idea behind the joint statement (the one to which I point is from the UK’s National Crime Agency) is:

The announced implementation of E2EE on META platforms Instagram and Facebook is an example of a purposeful design choice that degrades safety systems and weakens the ability to keep child users safe. META is currently the leading reporter of detected child sexual abuse to NCMEC. The VGT has not yet seen any indication from META that any new safety systems implemented post-E2EE will effectively match or improve their current detection methods.

From my point of view, a questionable “player” has an opportunity to make it possible to enforce laws related to human trafficking, child safety, and related crimes like child pornography. The “player” seems interested in implementing encryption that would make government enforcement more difficult, if not impossible in some circumstances.

The actions of this “player” illustrate what’s part of a fundamental change in the Internet. What was underground is now moving above ground. The implementation of encryption in messaging applications is a big step toward making the “regular” Internet or what some called the Clear Web into a new version of the Dark Web. Not surprisingly, the Dark Web will not go away, but why develop Dark Web sites when Clear Web services provide communications, secrecy, the ability to transmit images and videos, and perform financial transactions related to these data. Thus the Clear Web is falling into the shadows.

My team and I are not pleased with ignoring appropriate and what we call “ethical” behavior with specific actions to increase risks to average Internet users. In fact, some of the “player’s actions” are specifically designed to make the player’s service more desirable to a market segment once largely focused on the Dark Web.

More than suggestions are needed in my opinion. Direct action is required.

Stephen E Arnold, April 26, 2023

Is the UK Stupid? Well, Maybe, But Government Officials Have Identified Some Targets

February 27, 2023

I live in good, old Kentucky, rural Kentucky, according to my deceased father-in-law. I am not an Anglophile. The country kicked my ancestors out in 1575 for not going with the flow. Nevertheless, I am reluctant to slap “even more stupid” on ideas generated by those who draft regulations. A number of experts get involved. Data are collected. Opinions are gathered from government sources and others. The result is a proposal to address a problem.

The write up “UK Proposes Even More Stupid Ideas for Directly Regulating the Internet, Service Providers” makes clear that governments have not been particularly successful with its most recent ideas for updating the UK’s 1990 Computer Misuse Act. The reasons offered are good; for example, reducing cyber crime and conducting investigations. The downside of the ideas is that governments make mistakes. Governmental powers creep outward over time; that is, government becomes more invasive.

The article highlights the suggested changes that the people drafting the modifications suggest:

  1. Seize domains and Internet Protocol addresses
  2. Use of contractors for this process
  3. Restrict algorithm-manufactured domain names
  4. Ability to go after the registrar and the entity registering the domain name
  5. Making these capabilities available to other government entities
  6. A court review
  7. Mandatory data retention
  8. Redefining copying data as theft
  9. Expanded investigatory activities.

I am not a lawyer, but these proposals are troubling.

I want to point out that whoever drafted the proposal is like a tracking dog with an okay nose. Based on our research for an upcoming lecture to some US government officials, it is clear that domain name registries warrant additional scrutiny. We have identified certain ISPs as active enablers of bad actors because there is no effective oversight on these commercial and sometimes non-governmental organizations or non-profit “do good” entities. We have identified transnational telecommunications and service providers who turn a blind eye to the actions of other enterprises in the “chain” which enables Internet access.

The UK proposal seems interesting and a launch point for discussion, the tracking dog has focused attention on one of the “shadow” activities enabled by lax regulators. Hopefully more scrutiny will be directed at the complicated and essentially Wild West populated by enablers of criminal activity like human trafficking, weapons sales, contraband and controlled substance marketplaces, domain name fraud, malware distribution, and similar activities.

At least a tracking dog is heading along what might be an interesting path to explore.

Stephen E Arnold, February 27, 2023

A Convenient Deep-Fake Time Saver

February 1, 2023

There are some real concerns about deepfakes, and identifying AI imposters remains a challenge. Amid the excitement, there is one outfit determined to put the troublesome tech to use for average folks. We learn about a recent trial run in Motherboard‘s piece, “Researcher Deepfakes His Voice, Uses AI to Demand Refund from Wells Fargo.” 

Yes, among other things, Do Not Pay is working to take the tedium out of wrangling with customer service. Writer Joseph Cox describes a video posted on Twitter by founder Joshua Browder in which he uses an AI copy of his voice to request a refund for certain wire transfer fees. In the clip, the tool appears to successfully negotiate with a live representative, though a Wells Fargo spokesperson claims this was not the case and the video was doctored. Browder vigorously insists it was not. We are told Motherboard has requested a recording of the call from Wells Fargo’s side, but they had apparently not supplied on as of this writing. Cox writes:

“‘Hi, I’m calling to get a refund for wire transfer fees,’ the fake Browder says around half way through the clip. The customer support worker then asks for the callers first and last name, which the bot dutifully provides. For a while, the bot and worker spar back and forth on which wire transfer fees the bot is calling about, before settling on the fees for the past three months. In a tweet, Browder said the tool was built from a combination of, a site that lets users create their own AI voices, GPT-J, an open source casual language model, and Do Not Pay’s own AI models for the script. Do Not Pay has previously used AI-powered bots to negotiate Comcast bills. The conversation from this latest bot is very unnatural. There are long pauses where the bot processes what the customer support worker has said, and works on its response. You can’t help but feel bad for the Wells Fargo worker who had to sit silently while the bot slowly did its thing. But in this case, the bot was effective and did manage to secure the refunds, judging by the video.”

Do Not Pay does plan to make this time-saving tool available to the public, though equipping it with one’s own voice will be a premium option. As uses for deep fake technology go, this does seem like one of the least nefarious. Corporations like Wells Fargo, however, may disagree.

Cynthia Murrell, February 1, 2023

Social Media Scam-A-Rama

January 26, 2023

The Internet is a virtual playground for scam artists.  While it is horrible that bad actors can get away with their crimes, it is also impressive the depth and creativity they go to for “easy money.”  Fortune shares the soap opera-worthy saga of how: “Social Media Influencers Are Charged With Feeding Followers ‘A Steady Diet Of Misinformation’ In A Pump And Dump Stock Scheme That Netted $100 Million.”

The US Justice Department and the Securities and Exchange Commission (SEC) busted eight purported social media influencers who specialized in stock market trading advice.  From 2020 to April 2022, they tricked their amateur investor audience of over 1.5 million Twitter users to invest funds in a “pump-and-dump” scheme.  The scheme worked as follows:

“Seven of the social-media influencers promoted themselves as successful traders on Twitter and in Discord chat rooms and encouraged their followers to buy certain stocks, the SEC said. When prices or volumes of the promoted stocks would rise, the influencers ‘regularly sold their shares without ever having disclosed their plans to dump the securities while they were promoting them,’ the agency said. ‘The defendants used social media to amass a large following of novice investors and then took advantage of their followers by repeatedly feeding them a steady diet of misinformation,’ said the SEC’s Joseph Sansone, chief of the SEC Enforcement Division’s Market Abuse Unit.”

The ring’s eighth member hosted a podcast that promoted the co-conspirators as experts.  The entire group posted about their luxury lifestyles to fool their audiences further about their stock market expertise.

All of the bad actors could face a max penalty of ten to twenty-five years in prison for fraud and/or unlawful monetary transactions.  The SEC is cracking down on cryptocurrency schemes given the large number of celebrities who are hired to promote schemes.  The celebrities claim to be innocent, because they were paid to promote a product and were not aware of the scam.  

However, how innocent are these people when they use their status to make more money off their fans?  They should follow Shaq’s example and research the products they are associated with before accepting a check…unless they are paid in cryptocurrency.   That would be poetic justice!

Whitney Grace, January 26, 2023

The LaundroGraph: Bad Actors Be On Your Toes

January 20, 2023

Now here is a valuable use of machine learning technology. India’s DailyHunt reveals, “This Deep Learning Technology Is a Money-Launderer’s Worst Nightmare.” The software, designed to help disrupt criminal money laundering operations, is the product of financial data-science firm Feedzai of Portugal. We learn:

“The Feedzai team developed LaundroGraph, a self-supervised model that might reduce the time-consuming process of assessing vast volumes of financial interactions for suspicious transactions or monetary exchanges, in a paper presented at the 3rd ACM International Conference on AI in Finance. Their approach is based on a graph neural network, which is an artificial neural network or ANN built to process vast volumes of data in the form of a graph.”

The AML (anti-money laundering) software simplifies the job of human analysts, who otherwise must manually peruse entire transaction histories in search of unusual activity. The article quotes researcher Mario Cardoso:

“Cardoso explained, ‘LaundroGraph generates dense, context-aware representations of behavior that are decoupled from any specific labels.’ ‘It accomplishes this by utilizing both structural and features information from a graph via a link prediction task between customers and transactions. We define our graph as a customer-transaction bipartite graph generated from raw financial movement data.’ Feedzai researchers put their algorithm through a series of tests to see how well it predicted suspicious transfers in a dataset of real-world transactions. They discovered that it had much greater predictive power than other baseline measures developed to aid anti-money laundering operations. ‘Because it does not require labels, LaundroGraph is appropriate for a wide range of real-world financial applications that might benefit from graph-structured data,’ Cardoso explained.”

For those who are unfamiliar but curious (like me), navigate to this explanation of bipartite graphs. The future applications Cardoso envisions include detecting other financial crimes like fraud. Since the researchers intend to continue developing their tools, financial crimes may soon become much trickier to pull off.

Cynthia Murrell, January 20, 2022

