Modern WisdomWhat Is An Ethical Hacker? | Thomas Johnson | Modern Wisdom Podcast 105
CHAPTERS
- 0:00 – 1:27
Data is the new oil: why cyber conflict is the future of war
Tom frames modern hacking in geopolitical terms: data has become a strategic resource more valuable than oil. Because cyber capabilities are relatively cheap compared to traditional military assets, information warfare is positioned as the next dominant battleground.
- •Data is a high-value target driving massive investment in security
- •State threat actors (China, Russia, North Korea) and political rivals are central risks
- •Cost asymmetry: one fighter jet vs. hundreds of hackers
- •Information warfare as the future of conflict
- 1:27 – 2:31
Defining social engineering: hacking the human, not the machine
Tom explains social engineering as manipulating human psychology to elicit secrets or actions a person shouldn’t take. Even expensive technical defenses can be bypassed if someone is tricked into handing over access.
- •Social engineering = misuse of psychology to extract info or prompt risky actions
- •Humans can bypass technical controls (passwords, USB drops, access)
- •The ‘keys to the kingdom’ problem: user behavior undermines security spend
- •Ethical framing of how these techniques are used in legitimate tests
- 2:31 – 3:20
Your best defense: pattern recognition and the ‘gut feeling’ signal
Rather than portraying people as purely weak links, Tom argues humans can be strong detectors of suspicious patterns. He describes ‘gut feeling’ as subconscious pattern recognition that can interrupt manipulation attempts.
- •Humans are both the weakest and strongest link in security
- •Gut feeling as subconscious detection of anomalies in behavior/patterns
- •Training awareness can strengthen defenses against social engineering
- •Listening to intuition as an anti-con tactic
- 3:20 – 6:01
Origin story: early hacking, mischief, and the internet as a playground
Tom recounts how being pulled from school led to heavy computer use, game copying, and deeper curiosity about how systems work. With early internet access and little ethical guidance, curiosity escalated into risky experimentation.
- •Early exposure: games → copying → learning programming
- •Young curiosity without a developed moral/ethical compass
- •Hacking ‘random computers’ escalated as boredom increased
- •Dial-up era and early ‘always online’ obsession
- 6:01 – 7:05
Getting caught (sort of): the ‘police arrest’ that was a social engineering lesson
Tom describes being ‘arrested’ as a teenager and threatened with extreme consequences—only to learn decades later it was staged by his mother’s police friends to scare him straight. The incident became his first vivid demonstration of social engineering’s power.
- •A staged arrest used fear and authority to change behavior
- •Revealed later as a deliberate social engineering intervention
- •Long-term impact: avoidance of computers and reassessment of direction
- •Shows how effective psychological pressure can be
- 7:05 – 8:45
From black-hat impulses to white-hat career: university, ethics, and credentials
After stepping away from computers and experiencing business failure, Tom chose cybersecurity as a legitimate path. He ‘blagged’ his way into university, excelled academically, and reframed himself explicitly as a white-hat operating within the law.
- •Cybersecurity evolved from ‘crime’ to recognized profession
- •White-hat identity: ethics and legality as boundaries
- •Non-traditional entry: no qualifications → university opportunity
- •Academic success and rebuilding credibility
- 8:45 – 10:24
Offline social engineering in action: cloning university smart cards
Tom shares an early ethical hack where he reverse-engineered a university smart card system, built a cloner, and used disguise to skim staff cards. The result demonstrated how physical access and human trust can defeat institutional controls.
- •Rapid understanding of access card systems and cloning approach
- •Disguise and role-play (security guard) to avoid suspicion
- •Access gained: restricted areas, perks, and persistence of risk
- •Public talk disclosure created attention and career momentum
- 10:24 – 13:13
Recognition and escalation: speaking to law enforcement and the Home Office/FBI connection
A talk about his work led to invitations at high-level cybersecurity and forensics events. Tom describes presenting to hundreds of top professionals and receiving notable recognition, symbolizing his shift from teenage hacking to working alongside institutions.
- •Invited to Europe’s major closed cybersecurity convention (law enforcement/military)
- •Keynote setting and the pressure of presenting to experts
- •Home Office plaque and an ‘honor coin’ with major agencies represented
- •Personal arc: from scanning targets as a kid to professional collaboration
- 13:13 – 15:00
Building the technical toolkit: OSCP, Kali Linux, and the social vs technical skill gap
Tom explains his focus on OSCP and why it’s globally respected, grounding his work in penetration testing methodology. He also contrasts the abundance of technical hackers with the relative scarcity of strong social engineers who can persuade in person.
- •OSCP/PWK and Kali Linux as foundational technical track
- •Certifications as career accelerators and credibility signals
- •More great technical hackers than great social engineers
- •Rare combination: deep technical ability + strong interpersonal skills
- 15:00 – 16:54
Inside a real corporate test: reconnaissance, pretexts, and rapid physical compromise
Tom walks through an unnamed company engagement where he researched staff, built profiles, tested multiple pretexts, and used a fabricated project meeting to gain trust. With cloned access, he entered secure areas quickly and remained for hours largely unquestioned.
- •Recon phase: social media, staff mapping, prioritizing targets
- •Pretexting as iterative experimentation with ‘lies’ that work
- •Cloning access cards and moving through multi-door controls fast
- •Success defined by realistic attacker pathways, not just tech weaknesses
- 16:54 – 18:54
Hacker gadgets explained: Rubber Ducky, Bash Bunny, and stealth payload delivery
Tom explains popular physical attack tools that masquerade as benign USB devices. These devices emulate trusted peripherals to execute scripted actions at high speed, enabling local compromise even when users believe they’re protected.
- •USB Rubber Ducky emulates a keyboard to type payloads at extreme speed
- •Bash Bunny as a multi-attack platform (e.g., ethernet over USB)
- •Why these tools bypass typical user suspicion and some security controls
- •Physical access + trusted device assumptions are core vulnerabilities
- 18:54 – 27:24
From covert cameras to software-defined radio: the expanded attack surface (including cars)
The conversation broadens to small computers, hidden cameras, malware masking, and powerful SDR gear that can interact with many wireless technologies. Tom connects this to real-world crime such as keyless car theft via relay attacks and offers practical defenses.
- •Raspberry Pi/Zero and small hardware as portable ‘attack computers’
- •Hidden-camera devices and exfiltration via planted recording
- •Software-defined radio capabilities across Bluetooth/Wi‑Fi/NFC/GPS, etc.
- •Keyless car relay attacks explained; Faraday storage and key-motion mitigations
- 27:24 – 41:58
Password reality check: reuse, cracking strategies, and mnemonic generation
Using Chris’s own breach story, Tom explains credential stuffing and why password reuse is so damaging. He outlines how attackers use dictionaries and rules (not pure brute force) and offers a memorable method for generating strong passwords.
- •Credential stuffing: leaked credentials tested across many services
- •Why humans choose predictable password patterns (caps + numbers)
- •Rule sets/dictionaries and GPU cracking (Hashcat) speed up attacks
- •Mnemonic sentence → first letters/symbols method for strong memorable passwords
- 41:58 – 51:37
When attackers have a country behind them: Stuxnet, medical devices, and ‘good vs evil’ tools
Tom details how nation-state capabilities dwarf individual attackers, using Stuxnet as a landmark example of cyber causing physical destruction. He also discusses research into medical device vulnerabilities and reframes hacking as a tool—morally defined by who wields it.
- •Stuxnet targeted air-gapped Iranian systems via removable media and zero-days
- •Cyber operations can cause physical damage by manipulating industrial controllers
- •Barnaby Jack’s work on ATMs and medical device attack surfaces
- •Hacking as a neutral tool: Gordon Ramsay vs Jeffrey Dahmer analogy
- 51:37 – 1:01:16
Everyday exposure: IoT risk, Google dorking, live CCTV compromise, and what individuals can do
Tom emphasizes that many real-world compromises are ‘low skill’ due to misconfiguration, showing how advanced Google search operators can expose cameras and systems. He shares practical guidance: unique passwords, email as the crown jewel, cautious device purchasing, and broad security awareness.
- •Common-sense hygiene: don’t reuse passwords; protect email account first
- •IoT devices can undermine security if cheaply made or poorly configured
- •Google dorking/‘Google hacking’ finds exposed systems via search operators
- •Live demo: remotely controlling a misconfigured university CCTV camera
- 1:01:16 – 1:04:20
The security talent gap and how to get started (legally)
Closing out, Tom highlights strong compensation and a looming workforce shortage in cybersecurity. He recommends beginner-friendly legal training platforms and encourages listeners to pursue the field as a meaningful career change.
- •Pen tester salary range and demand-driven opportunity
- •Projected large cybersecurity job deficit
- •Learn ethically via Hack The Box and OverTheWire wargames
- •Build skills with Kali Linux and training platforms like Immersive Labs