Modern WisdomWhat Is An Ethical Hacker? | Thomas Johnson | Modern Wisdom Podcast 105
EVERY SPOKEN WORD
120 min read · 23,971 words- 0:00 – 1:27
Data is the new oil: why cyber conflict is the future of war
- TJThomas (Tom) Johnson
To me, you've got to understand that data now is worth more than oil. Um, so they're going to put a lot of money into securing that, and they're gonna put a lot of money into defending that. Now, I'm genuinely proud of, of living in England and in Britain, because we have some of the best security professionals in the world. But you have a lot of threat actors as well. So you've got China, you've got Russia, you've got North Korea. You've got all the states that wouldn't necessarily get on with us politically. And you have to understand that for the price of one fighter plane, you can hire 200 hackers. So information warfare is going to be the future of war.
- CWChris Williamson
I am joined by Tom Johnson, ethical hacker and social engineer extraordinaire. Welcome to the show, Tom. It's great to have you on.
- TJThomas (Tom) Johnson
Hello. Thank you very much for inviting me.
- CWChris Williamson
Uh, it's gonna be an exciting one today. This world of ethical hacking and social engineering is something that I've seen a little bit about online, but I don't really know all that much. But I guess we're gonna, we're gonna delve into it today, right?
- TJThomas (Tom) Johnson
Absolutely, yeah. I mean, would you like to start off at the beginning, how I got involved in it?
- CWChris Williamson
Yeah, absolutely.
- TJThomas (Tom) Johnson
Or would you like me to tell you what it is, first of all? (laughs)
- CWChris Williamson
(laughs) No. So yeah-
- TJThomas (Tom) Johnson
(laughs)
- CWChris Williamson
Let's, let's, let's find out. How do you define ethical hacking and, and social engineering and what you do? And then, and then let's find about, out about the, uh, the genesis story.
- 1:27 – 2:31
Defining social engineering: hacking the human, not the machine
- TJThomas (Tom) Johnson
Absolutely. Okay, so social engineering, according to a guy called Christopher Hadnagy in America, is the art of using human psychology or misusing human psychology to get a target to do something or say something they shouldn't do or say, and that is grassroots. So if you can talk someone into giving you the passwords or plugging a USB stick into the computer, then all of this very expensive sort of cybersecurity mitigation is useless, because they are literally giving you the keys to the kingdom. So that, in a nutshell, is what it is.
- CWChris Williamson
I understand. Yeah. I suppose as these, uh, technological firewalls, uh, and safety measures become more sophisticated, the, uh, ways around it that don't require you to just brute force try and break through something that's heavily encrypted, I guess this sort of falls to the, the one remaining weak link in the chain, which is always going to be the, the several-million-year-old brain that sits inside of the person controlling the system, right?
- 2:31 – 3:20
Your best defense: pattern recognition and the ‘gut feeling’ signal
- TJThomas (Tom) Johnson
(laughs) Well, uh, in my opinion, humans can be the weakest link, but they can also be the strongest link as well, because they think in a different way to how computers process information. So have you ever had a gut feeling before, Chris?
- CWChris Williamson
Mm-hmm. Yeah.
- TJThomas (Tom) Johnson
Well, that gut feeling is your subconscious mind telling you that there is something not quite right in a pattern. So your subconscious mind is constantly processing everything around you, and then when you get that gut feeling, that is your subconscious mind saying to your conscious mind, "There's something not quite right here." So that is a really good way to defend against social engineers.
- CWChris Williamson
Yeah.
- TJThomas (Tom) Johnson
That gut feeling.
- CWChris Williamson
Got you. Okay, so let's start off, the genesis story. How do you ... So h- what happens whereby you are now sat opposite me with a microphone in front of you talking about ethical hacking-
- TJThomas (Tom) Johnson
(laughs)
- CWChris Williamson
... and social engineering? Where does it begin?
- 3:20 – 6:01
Origin story: early hacking, mischief, and the internet as a playground
- TJThomas (Tom) Johnson
Right. It begins when I was about 12 years old, and I was pulled out of school by an overprotective mother. Um, I was a very small child in a predominantly council area in Wallsend, um, and it wasn't a very good time at school for me. And she was very overprotective, pulled me out, and had nothing to give me work-wise, so she just sat me in front of a computer. So I started playing games, what every child tends to do, and then I started getting bored of games. Um, and I couldn't afford new games, so I started working out how I could break the system and copy those games so I could get them for free. Not because I was a criminal, but because I wanted to play games. Uh, the games started getting boring, so I wanted to learn how the games worked. So I programmed the games, um, and things developed on and on and on. And then something amazing happened. This rudimentary thing called the internet come about, and it'd become my playground. Um, I was spending all of me time online. Um, I had no moral or ethical compass at that point in time. I was young. I, I wasn't a bad lad, but I'd done things because I was a bit mischievous. So I would hack random computers on the internet and download through all the ... Look through all the files, and then it started getting boring, so I started going a bit further. I started college. Um, I got thrown out of college for hacking an internal mail system.
- CWChris Williamson
(laughs)
- TJThomas (Tom) Johnson
I was ... (laughs) Yeah, I was naughty, but I was sending messages from one lecturer to another saying that they were in love with each other or, or all sorts of different things.
- CWChris Williamson
(laughs) Okay.
- TJThomas (Tom) Johnson
Getting some funny looks.
- CWChris Williamson
Yeah.
- TJThomas (Tom) Johnson
I was great at doing things, but terrible at getting away with them.
- CWChris Williamson
Ah, yeah.
- TJThomas (Tom) Johnson
So I actually got caught and, and thrown out of, uh, college. So I went back again. I lasted about two weeks, and I was thrown out again. Um, I locked the network manager out of his computer, and he didn't see the funny side.
- CWChris Williamson
(laughs)
- TJThomas (Tom) Johnson
So you've got to understand, at the same time, uh, uh, me skills were developing, um, to a point where college wasn't really teaching me anything. So I was a bit bored, if that makes sense. So it just sort of encouraged me to do more and more risky things, silly things when I look back. I'm a white hat now, may I just add that? A white hat is somebody who puts ethics over morals, over everything. So I will only act within the boundaries of law. But in those days, anything online was fair game. Um, I was running me mother's phone bill because of course it was on dial-up at the time.
- CWChris Williamson
(laughs)
- TJThomas (Tom) Johnson
Um, she used to put a little, um, key code on, so I wrote a little program that would go through every single key code and, and brute force it.
- CWChris Williamson
Ah. (laughs)
- 6:01 – 7:05
Getting caught (sort of): the ‘police arrest’ that was a social engineering lesson
- TJThomas (Tom) Johnson
So within an hour, I was back online again. And then one day, I heard a knock at the door. I answered the door, and there was two big, burly police officers standing in front of us. Um, they subsequently arrested me.... took me to the police station, locked me up for about 15 hours, threatened to extradite me to America where I'd get death by lethal injection and everything. And I was absolutely terrified. And in 20-
- CWChris Williamson
How old were you, how old were you here?
- TJThomas (Tom) Johnson
I was about 16, 17-ish.
- CWChris Williamson
Shit the bed. It's a young age-
- TJThomas (Tom) Johnson
And, uh-
- CWChris Williamson
... to be having such, uh, such, such heavy words thrown at you.
- TJThomas (Tom) Johnson
I'd had a, I'd had a slap about the head and everything.
- CWChris Williamson
Yeah, yeah, yeah.
- TJThomas (Tom) Johnson
And 20 years later, I found out it was a social engineering attack on us. It was actually two of my mother's friends who were coppers, who she put them up to the task of scaring me straight.
- CWChris Williamson
Oh, no way.
- TJThomas (Tom) Johnson
So it wasn't a real arrest. It was to fuck up with our phone bill. (laughs) So, that was my first taste of, of, um, social engineering, and believe you me, it was very effective.
- CWChris Williamson
Wow. So did that-
- TJThomas (Tom) Johnson
And then-
- CWChris Williamson
... did that scare you straight?
- 7:05 – 8:45
From black-hat impulses to white-hat career: university, ethics, and credentials
- TJThomas (Tom) Johnson
It scared me straight for a very long time. In fact, I lost me love of computers for a while. Um, I, I, I took it hook, line and sinker, and I was genuinely in fear of me life (laughs) . Um, and, and I just stayed away from computers. I set up a company. Um, I'd done all right out of the company. And then that went under and I just thought to meself, "What do I want to do? Do I want to earn minimum wage for the rest of me life?" So I looked at the skillset that I had and I thought, "I want to go back into cybersecurity." Now it is a, a job. It wasn't back then. It was a crime, but now it's a job. So, uh, I had no qualifications to me name, so I blagged me way onto a Tayside University course. Um, they give me a shot and I've received a, a first with honors in every module so far. So, I've done all right.
- CWChris Williamson
Amazing. That's fantastic.
- TJThomas (Tom) Johnson
Yeah. Thank you.
- CWChris Williamson
So, that's, that's the journey that you've taken yourself on there. So, how do you go from the online to the offline? Is it off- offline hacking?
- TJThomas (Tom) Johnson
Right, yeah. Well, it's, it's more in person. It, it, it's like, it's like the, the good old-fashioned con. That's exactly what it is, but it's got a cyber element to it.
- CWChris Williamson
Okay.
- TJThomas (Tom) Johnson
So, if you remember the old conmen or conwomen who would trick you into doing something, that is exactly what social engineering can be.
- CWChris Williamson
Mm-hmm.
- TJThomas (Tom) Johnson
It's tricking somebody into doing something or saying something they shouldn't. So, I set up a little company. Um, I started doing a little bit of work with the police, um, little bits and bobs here and there. Um, and then I done a talk at Cyberfest. Have you heard of Cyberfest, the convention?
- CWChris Williamson
No.
- 8:45 – 10:24
Offline social engineering in action: cloning university smart cards
- TJThomas (Tom) Johnson
It's, it's a north- northeast convention, Northeast of England. Um, and then I was invited from that talk, um, to do a talk at the, um, local government level. Now, the talk that I done was based upon a hack that I carried out, an ethical hack, on the university that I studied at. So, I was a first-year student, bearing in mind, when this took place and I approached the school of computing, "Can I test your security, please?"
- CWChris Williamson
Hmm.
- TJThomas (Tom) Johnson
And they said yes. They didn't realize I'd been a hacker from being about 12 years old.
- CWChris Williamson
Oh, did they just think that it was some, some student who didn't really know what he was doing? Didn't realize they were coming up against boss level 55 hacking skills?
- TJThomas (Tom) Johnson
(laughs) I wouldn't say I'm that good. Uh, but yeah, they, they, they got a bit of a shock. Um, within 24 hours, I worked out how their, um, smart card system worked and I built a cloner that could clone the cards. So I then dressed up as a security guard, and this is the social engineering side of things, put the high-vis on, done me Superman change, shaved me head, looked completely different, and then went round and skimmed all of the staff's cards. Um, and with those cards I had access to all areas, free parking for six months me I had.
- CWChris Williamson
(laughs)
- TJThomas (Tom) Johnson
Um, free food (laughs) , free food, um, library books. Everything you could ever want was all there, free. Um, I didn't tell Tayside University until Cyberfest, which was a little bit naughty.
- CWChris Williamson
Oh.
- TJThomas (Tom) Johnson
Um, and then I sort of gave away all the secrets and it got a little bit of attention. (laughs)
- CWChris Williamson
I bet it did, yeah.
- 10:24 – 13:13
Recognition and escalation: speaking to law enforcement and the Home Office/FBI connection
- TJThomas (Tom) Johnson
It did. Um, but then I got invited to the ICDDF, the Information, Communication, Data and Digital Forensics Convention, which is, uh, Europe's largest closed cybersecurity convention for, uh, police, law enforcement and military. So I was invited by the National Police Chief's Council to do a talk there. Um-
- CWChris Williamson
Real epicenter of, of this sort of stuff then.
- TJThomas (Tom) Johnson
Absolutely, absolutely. It's about as big as you can get. Um, it was invite only, you know, you couldn't get through the doors unless you were invited. So I arrived, um, I expected to be shut in a little side room, just doing a little filler talk, and I was in the big county suite, uh, and I was a keynote speaker, so it was absolutely terrifying.
- CWChris Williamson
(laughs)
- TJThomas (Tom) Johnson
So I had to talk in front of 600 of some of the world's best professionals on cybersecurity and, and especially social engineering.
- CWChris Williamson
Shit the bed.
- TJThomas (Tom) Johnson
Absolu- Do you wanna see what I got as well? I got that.
- CWChris Williamson
What's that? That's a plaque. Certificate of-
- TJThomas (Tom) Johnson
It's a cert-
- CWChris Williamson
... Appreciation. That's so cool. That's from-
- TJThomas (Tom) Johnson
It i-
- CWChris Williamson
Is that from the Home Office?
- TJThomas (Tom) Johnson
That's from the Home Office, yeah. Um, let me just see. I've got something else kicking about somewhere. (rustling) Oh, there it is. Bear with me one moment. I've dropped it. This is even cooler. This is an honor coin that I was given, believe it or not, off the Home Office-
- CWChris Williamson
Okay.
- TJThomas (Tom) Johnson
... and the FBI.
- CWChris Williamson
Oh. So it's an AT&T NTAC-
- TJThomas (Tom) Johnson
This-
- CWChris Williamson
What, what does, what does that mean and what is it? It's like a big plastic-
- TJThomas (Tom) Johnson
So, it-
- CWChris Williamson
... plastic coin.
- TJThomas (Tom) Johnson
No you know, it's not. It's a metal coin. (laughs)
- CWChris Williamson
Metal c- Oh, inside of a pla- inside of a plastic sleeve?
- TJThomas (Tom) Johnson
It's in a plastic container. See if I can get it out for you.
- CWChris Williamson
Oh, right. Yeah, yeah. So what, what does it mean?
- TJThomas (Tom) Johnson
And-
- CWChris Williamson
What does it do?
- TJThomas (Tom) Johnson
Oh, it's stuck. So this is what you call an honor coin. Um, and it's what I was awarded for doing the talk.Um, and it- I'll show you. So, that's the side there, that's the important one.
- CWChris Williamson
Okay.
- TJThomas (Tom) Johnson
That's, uh, the National Police Chief's Council, our central government-
- CWChris Williamson
Yeah, yeah.
- 13:13 – 15:00
Building the technical toolkit: OSCP, Kali Linux, and the social vs technical skill gap
- TJThomas (Tom) Johnson
I'm getting a fair few job offers all the time, to be, to be fair. Um, but I'm currently putting them on hold. I've went on another journey now, which is the technical side. I'm currently studying, uh, OSCP, which is Offensive Security Certified Professional hacker. Um, I should receive that in two months. And then (claps hands) the world is my oyster.
- CWChris Williamson
What's that most recent qualification? What does that mean?
- TJThomas (Tom) Johnson
Um, that is... We have an operating system, and you'll see it just behind me here.
- CWChris Williamson
Yeah.
- TJThomas (Tom) Johnson
That's a Kali Linux, which is not a Windows-based system, it's a, it's a Debian-based system. And, uh, Offensive Security, who make Kali Linux have an accreditation called OSCP. Um, and it's called PWK, Penetration With Kali Linux. So once I get that, it's a- a globally recognized certification.
- CWChris Williamson
Okay. And that is, like you said, on the technical side. So is it rare to find, uh, hackers who have the in-person skills alongside the technical know-how? Or do you find-
- TJThomas (Tom) Johnson
I think-
- CWChris Williamson
Do you find- do you find people who have that mindset with regards to just trying to open doors? Whether it's online or offline, they're just interested either way?
- TJThomas (Tom) Johnson
I think you have more technological hackers than you have social engineers. Um, s- sorry, let's rephrase that. You have more good technical hackers than you have good social engineers.
- CWChris Williamson
Gotcha.
- TJThomas (Tom) Johnson
So every- every hacker has the potential to attempt social engineering-
- CWChris Williamson
Mm-hmm. Mm-hmm.
- TJThomas (Tom) Johnson
... techniques and- and tactics, but some are better than others. Um, and- and it's relatively rare to find a nerd like meself with the ability to be able to talk to people as well.
- CWChris Williamson
Mm.
- 15:00 – 16:54
Inside a real corporate test: reconnaissance, pretexts, and rapid physical compromise
- TJThomas (Tom) Johnson
So I take pleasure in teaching and- and communicating and- and helping organizations. And that in itself helps me sort of sharpen me social engineering toolset. Um, I've recently done a hack on a- on a large unnamed company.
- CWChris Williamson
Mm-hmm.
- TJThomas (Tom) Johnson
Um, uh, uh, an ethical hack. I was employed to test their security. Um, and part of my training them allowed me to advance my social engineering, and I'll explain that. W- I was- I was approached by this company and asked if I could test their human firewall. So I spent three, about three weeks exfiltrating information, um, doing reconnaissance on them, passive and active, finding out who the staff were who they were talking to. Um, I trolled all of the Facebooks, the LinkedIn, all of the social media. I built up profiles on them. I prioritized five staff, um, who I thought would be the weakest, and I approached them over LinkedIn for my pretext, which was my lie. So I tried, um, multiple... I'll not go into the trade secrets, but I tried multiple lies and a couple of them were successful. I- I managed to- to hook a couple of them, but one I prioritized. I went and I held a meeting with them pertaining to something that didn't exist, um, and then left. And in that short amount of time I had already cloned all of the cards to get into the building.
- CWChris Williamson
(laughs)
- TJThomas (Tom) Johnson
Um, so within 15 minutes of my actual, um, exploitation phase, I was in their inner sanctum through multiple coded doors, drinking cups of coffee in their tea station for three and a half hours unquestioned. Um, it was- it was good. It was interesting. It was exciting.
- CWChris Williamson
Is that- is that what you call a successful hack?
- 16:54 – 18:54
Hacker gadgets explained: Rubber Ducky, Bash Bunny, and stealth payload delivery
- TJThomas (Tom) Johnson
Yes. Um, to- to be totally honest with you, they were very good on a lot of areas, um, but th- th- they just didn't expect an attack of that magnitude to take place. So the final straw was I was asking staff to step away from the computers when I was plugging in, um, covert, um, hacking tools, like the USB Rubber Ducky and the Bash Bunny, which look like USB devices but they aren't. Um, the- the tools-
- CWChris Williamson
Tell us- tell us about those. I want to know what those do.
- TJThomas (Tom) Johnson
Right. Well, uh, USB Rubber Ducky was created by a company called Hak5. Shout-out to Shannon Morse and Darren Kitchen. Um, they created, um, a- a device called an HID, a human, uh, interface device. Now, it looks to the computer like it's a keyboard with somebody typing on the other end-
- CWChris Williamson
Okay.
- TJThomas (Tom) Johnson
... but it can type at thousands of characters a minute. So I could spend a full day coding exploits to- to compromise their systems, and then I plug this device in and it types it out locally-
- CWChris Williamson
Ah, yes. Okay.
- TJThomas (Tom) Johnson
... on the system. Yeah. So it- it thinks it's a person typing. And the Bash Bunny is an attack, a multi-attack platform, um, which can emulate, uh, ethernet over USB, which is trusted by Windows, iOS and Linux-... um, and you can run payloads, steal password hashes, do all sorts with it, even through a lock screen on a computer.
- CWChris Williamson
Shit the bed.
- TJThomas (Tom) Johnson
Yeah. Yeah. (laughs)
- CWChris Williamson
This is serious stuff.
- TJThomas (Tom) Johnson
Oh, it gets worse. It gets worse. (laughs)
- CWChris Williamson
Oh, come on. I want to find out, what are the other, what's the other, like, atomic weapons? Or what ... If we were to open up the ethical hacker's toolkit or the bag, what have you got inside of it? You've got the rubber ducky, you've got-
- TJThomas (Tom) Johnson
I've, I've got all sort of things.
- CWChris Williamson
... the bash, you've got the bash bunny.
- TJThomas (Tom) Johnson
In fact, I've got, I've got some bits here if you want me to show you them.
- CWChris Williamson
You can just run-
- TJThomas (Tom) Johnson
Would you like me to show them?
- CWChris Williamson
You can just run through them if you want to. You can just run us through everything that'd be in there.
- 18:54 – 27:24
From covert cameras to software-defined radio: the expanded attack surface (including cars)
- TJThomas (Tom) Johnson
Right. Okay. Well, I've got them, and I'll show you at the same time.
- CWChris Williamson
Cool.
- TJThomas (Tom) Johnson
So we've got, um, little single board computers, Raspberry Pis. Really useful, they run off a battery. Uh, they've got wifi, Bluetooth, and that's a full PC there.
- CWChris Williamson
Okay.
- TJThomas (Tom) Johnson
Um, but they do get smaller. You can get the little Raspberry Pi Zeroes, which are absolutely tiny.
- CWChris Williamson
That's ju- n- not much bigger than the size of a matchbox, but it's essentially a computer in your, in your pocket.
- TJThomas (Tom) Johnson
Pretty much. But they get even smaller.
- CWChris Williamson
And that's one-
- TJThomas (Tom) Johnson
That is the full PC there.
- CWChris Williamson
... that is one which is probably the size of, just bigger than a lighter, but totally two-dimensional.
- TJThomas (Tom) Johnson
Well, there's a USB stick.
- CWChris Williamson
Yeah.
- TJThomas (Tom) Johnson
And there's a-
- CWChris Williamson
About ... Just a bit bigger than a USB stick. Yeah. Wow.
- TJThomas (Tom) Johnson
Yeah. So that's how you-
- CWChris Williamson
Unbelievable.
- TJThomas (Tom) Johnson
... how you ... So just standard USB sticks with, uh, malicious software on them.
- CWChris Williamson
Okay. Yeah.
- TJThomas (Tom) Johnson
Uh, you can, you can generate malware, and then you can, um, use a crypter, like Veil Evasion, to mask its file signature-
- CWChris Williamson
Okay.
- TJThomas (Tom) Johnson
... so the antivirus, uh, systems don't pick up on it.
- CWChris Williamson
Okay.
- TJThomas (Tom) Johnson
So the very system that you use to protect you works against you because it doesn't flag you of any problems.
- CWChris Williamson
Perfect. And you, and you think that you're safe as well, so you're probably-
- TJThomas (Tom) Johnson
Absolutely.
- CWChris Williamson
... probably a little bit more complacent about the security that you should have in place. "Oh, well, even if someone does get through, the antivirus will catch it."
- TJThomas (Tom) Johnson
Yeah. Absolutely. So we've got a, a normal, like that cheapy six quid off eBay, really useful. It's got a little covert camera in the bottom of it.
- CWChris Williamson
No way.
- TJThomas (Tom) Johnson
And this bit comes off and it's a, it's a USB stick. Really handy, leave them in cigarette areas and stuff to, to record stuff and then exfiltrate information from that.
- CWChris Williamson
That's awful.
- 27:24 – 41:58
Password reality check: reuse, cracking strategies, and mnemonic generation
- CWChris Williamson
Fucking hell. So, um, LinkedIn had a data breach not so long ago, uh, and a bunch of, um, a bunch of logins, uh, account information was taken from that. Mine was one of them. One thing that I didn't do, although I have done now with a, a updated password protector, shout out to 1Password, Tiago Forte's suggestion to me, which has been an absolute lifesaver. Um, I had the same password for LinkedIn as my Deliveroo, um, and-
- TJThomas (Tom) Johnson
No, no!
- CWChris Williamson
... I know, I-
- TJThomas (Tom) Johnson
Don't share passwords!
- CWChris Williamson
I know, I know.
- TJThomas (Tom) Johnson
Do not share passwords.
- CWChris Williamson
That was a bad, that was a bad idea. And, um-
- TJThomas (Tom) Johnson
Yeah.
- CWChris Williamson
... so, I, I got a mess- woke up one morning with a message off my business partner, and he said, uh, uh, "Is this you ordering Nandos in London on my card?" 'Cause his card was on my account. I must have ordered something for him.
- TJThomas (Tom) Johnson
(laughs)
- CWChris Williamson
So, uh, I was like, "No. No, no, not at all. Not at all." Went on-
- TJThomas (Tom) Johnson
(laughs) I shouldn't laugh, I'm sorry.
- CWChris Williamson
Oh, it's okay. It wasn't my money, it was his. Although he did, he, he then did, uh, make sure that I was billed for it on the company account. But, uh, yeah, and then sure enough-
- TJThomas (Tom) Johnson
(laughs)
- CWChris Williamson
... they, they'd used my details and they must have just brute force checked a whole bunch of other platforms to see, does this email and password combination appear on this, this, this, this, this, this, this, this, this? And sure enough, on Deliveroo it did. And 45 quid worth-
- TJThomas (Tom) Johnson
Absolutely.
- CWChris Williamson
... of Nandos later, they'd, they'd had it away.
- TJThomas (Tom) Johnson
That is social engineering 101. The human psychology make... The way that you're wired makes it difficult to remember complex random passwords, so what we do is we create something that we know. Most passwords have a capital first letter and have numbers at the end. Why? Because through school, we're taught to capitalize the first letter of a sentence. So when we're generating our password, we capitalize the first letter 'cause we know it needs a capital.
- CWChris Williamson
Mm-hmm.
- TJThomas (Tom) Johnson
We're putting the number at the end because it's at the end and we'll remember it. It's normally two digits or four digits, a date of birth, or a memorable date, um, or something simple like one, two, three, four at the end of the password. Passwords are normally constructed out of, if you're English, English words, um, which can be found in a dictionary. Um, and it doesn't take very long to crack a password. The entire character set of eight characters, including uppercase, lowercase, numbers, and special characters, in its entirety, can be cracked in two hours now. So, I mean-
- CWChris Williamson
Jesus Christ.
- TJThomas (Tom) Johnson
(laughs) Yeah. If, if, if you're looking at longer passwords, if it's constructed of English words and numbers and letters, we use dictionary attacks, so we'll say, okay, we'll try dictionary one and dictionary two, and we'll use a rule set to capitalize the first letters, or not, and put numbers at the end from one to 3,000, and then that reduces that character set down massively. So you can, you can crack a lot of passwords relatively quickly.
- CWChris Williamson
Is that brute force stuff there, where you just start, you'll set some sort of program away and it will just start cycling through version one, version two, version three, version four?
- TJThomas (Tom) Johnson
No, brute force isn't very efficient. Uh, the eight-character set, which I said can be cracked in its entirety, that is a brute force attack.
- CWChris Williamson
Yes.
- TJThomas (Tom) Johnson
As you start getting to nine, 10, it's inconceivably long.
- CWChris Williamson
Yeah.
- TJThomas (Tom) Johnson
So what you do is you use rule sets-
- CWChris Williamson
Yes.
- TJThomas (Tom) Johnson
... and dictionaries.
- 41:58 – 51:37
When attackers have a country behind them: Stuxnet, medical devices, and ‘good vs evil’ tools
- TJThomas (Tom) Johnson
Nation state are on a whole new level. A whole new level. Have you heard of Stuxnet?
- CWChris Williamson
Uh, I've heard the name. I don't know why. What is it?
- TJThomas (Tom) Johnson
Stuxnet, um, without going into too much technical detail, it was a, uh, a virus that had infected a large volume of computers across the globe. Um, and it took Symantec several weeks to work out what this virus was. Normally, it takes them about 10, 15 minutes to say, "Oh, this is a worm, this is this, this is how it works, this is how it propagates."... but Stuxnet, they didn't know what it was for a long time. It had bits of code that they didn't know what it was and, and how it worked. And it was infecting computers on a level that they had never seen before. Um, it was infecting USB sticks, removable media, transferring it everywhere, and it wasn't doing anything. Yeah.
- CWChris Williamson
Oh, right.
- TJThomas (Tom) Johnson
And they were like-
- CWChris Williamson
Okay, just sitting there being, been very intimidating. (laughs)
- TJThomas (Tom) Johnson
Uh, no, it was being very quiet. That's the scary thing about it.
- CWChris Williamson
Yeah. Okay, yeah.
- TJThomas (Tom) Johnson
And it turned out, it was looking for one system, um, and that system was the Iranian Nuclear Enrichment Program. And this bug was so sophisticated, it had four zero-days in it, and a zero-day is worth about a million dollars. It's like a hole, an unknown hole in an operating system or a service.
- CWChris Williamson
Okay.
- TJThomas (Tom) Johnson
And this had four in it, which pointed to Nation State. And what it done when it found, um, this power plant, all this unknown code was to control the industrial controllers of the factory. So, what it done is it recorded, uh, stats covertly of the factory for about 30 days. It then disabled the safety mechanisms, 'cause they were all through a computer, and then it replayed the good stats. So, do you know, like in films, where the, the, they capture a bit of footage and then they'll loop that footage while they're committing a crime-
- CWChris Williamson
Mm-hmm.
- TJThomas (Tom) Johnson
... on a C- CCTV camera? Well, this was doing it on, doing it on a nuclear enrichment system. So, once it was playing back the good stats, it started speeding up and slowing down all the centrifuges until it exploded, and it blew up thousands of centrifuges, physically exploded.
- CWChris Williamson
This actually happened? When was this?
- TJThomas (Tom) Johnson
This actually happened, oh, 2009-ish, I think. I might be wrong.
- CWChris Williamson
Wow. I'm not, uh, s- I'm not massively au fait with news and stuff like that, so I very well might have missed it, but that is terrifying. And obviously, the, the implications are that could be for pretty much, you know, if they can get into the Iranian Nuclear Enrichment plant, like, what, what really is left after that? What's got more security than that?
- TJThomas (Tom) Johnson
(laughs) Well, the scary thing was, is it wasn't even connected to the internet.
- CWChris Williamson
Okay, right. So it was totally off-
- TJThomas (Tom) Johnson
So it wasn't connected-
- CWChris Williamson
... totally offline, totally isolated.
- TJThomas (Tom) Johnson
That's... Yeah, it was called air- air-gapped, so that's why they were infecting removable media. So one person plugged that stick into that computer and that system was doomed, absolutely doomed. I mean, there's, there's amazing things which happen all of the time. This device that I showed you before, the little, uh, radio transceiver, um, there was a guy called Barnaby Jack who was a New Zealand-based, uh, ethical hacker. Uh, he was the guy who used to hack bank machines, and he could dial something into his phone and then the bank machine would put JACKPOT on the screen and start emptying the cassettes of its money.
- CWChris Williamson
(laughs)
- TJThomas (Tom) Johnson
Yeah, he, he was a showman, an absolute showman, super genius. Um, he discovered that, um, pacemakers and morphine pumps, um, were, and insulin pumps, a lot of them, not all of them, uh, were susceptible to an SDR attack. So, he potentially could defibrillate the person by pressing enter on his keyboard-
- CWChris Williamson
Oh, my God.
- TJThomas (Tom) Johnson
... from about 100 yards away. Um, and he approached the big, uh, company and s- companies and said, "Look, you know, this is a major security flaw." And they said, "We're not interested." Um, so he was gonna sort of tell everyone how it was done at a big convention, and unfortunately he died before the convention.
- CWChris Williamson
Was that a suspicious death?
- TJThomas (Tom) Johnson
Who knows?
- CWChris Williamson
Well, he, he died.
- TJThomas (Tom) Johnson
Who knows?
- CWChris Williamson
He died.
- 51:37 – 1:01:16
Everyday exposure: IoT risk, Google dorking, live CCTV compromise, and what individuals can do
- CWChris Williamson
Does this need to happen at a state level or are there things that at, at an individual level which we all should be doing as well, apart from 12 string passwords and not using the password "password1"?
- TJThomas (Tom) Johnson
Uh, I think... I think governments do have a responsibility to protect us. Um, that's what we were elected for. And, uh, so far I think the UK have done a fantastic job, you know. There is gonna be attacks all the time but how many they stop and how many they defend against it, you know, we will never know.
- CWChris Williamson
Mm-hmm.
- TJThomas (Tom) Johnson
But they are doing their bit. Um, but I think common sense is a big thing. You know, don't just have super complex passwords but just don't share them between all sorts of different platforms, 'cause if I get your LinkedIn, there's a very good chance your email's gonna have the same password as your LinkedIn or something similar.
- CWChris Williamson
Mm-hmm.
- TJThomas (Tom) Johnson
So I'm gonna target your email 'cause then I can recover all your passwords to your email from all your other accounts.
- CWChris Williamson
Mm-hmm.
- TJThomas (Tom) Johnson
Does that make sense?
- CWChris Williamson
Mm-hmm.
- TJThomas (Tom) Johnson
Remember a few things. Whatever you put on the internet will always remain on the internet. There's no getting rid of it. It's gonna be there, it's gonna be spidered, it's gonna be captured. Um, if you're using IOT devices, so internet of things like, um, CCTV cameras and things like that, buy them from reputable places, you know. Do your homework. Um, if you're buying a camera from China that's 20 quid and the same one in, from a, a British manufacturer or whatever's 150 quid, there's a reason why.
- CWChris Williamson
(laughs)
- TJThomas (Tom) Johnson
Do you know what I mean?
- CWChris Williamson
(laughs)
- TJThomas (Tom) Johnson
Um, that reason tends to be the fact that they're, they're rubbish, they're crap, they don't protect you. In fact the very devices that we use to protect us sometimes works in the favor of the cyber criminals. One of my demonstrations is something called Google Dorking. Have you heard of Google Dorking?
- CWChris Williamson
No. Take us through it.
- TJThomas (Tom) Johnson
Really, really simple technique. It's, um, using advanced search operators in Google to look for misconfigured systems.
- CWChris Williamson
Right.
- TJThomas (Tom) Johnson
Um, now anybody can do it without any technical capabilities whatsoever. Um, they just need to know where to look. Now I'm not gonna tell you where to look-
- CWChris Williamson
Okay.
- TJThomas (Tom) Johnson
... but it's called, it's called Google Hacking-
- CWChris Williamson
Yeah.
- TJThomas (Tom) Johnson
... if you're interested in looking.
- CWChris Williamson
Yeah.
- TJThomas (Tom) Johnson
Um, and you can put in a string and you can exfiltrate, um, broken cameras or cameras... When I say broken, I mean cameras that aren't set up correctly. Now with one line of code I can find 500 web cameras that I can log into. Some of them are CCTV cameras. So, you know, it's- it's really, really scary stuff.
- CWChris Williamson
It is scary stuff. I, n- and some of the listeners will know I had, uh, Roger McNamee who was one of the early investors in Facebook, personal advisor to Mark Zuckerberg, he was the, the guy that got Sheryl Sandberg on board. Um, then, uh, just before that I spoke to Professor David Carroll who was the man-
- TJThomas (Tom) Johnson
Yeah.
- CWChris Williamson
... the professor from The Great Hack, uh, on Netflix. Spoke to both of those guys within a couple of days of each other and, um, it definitely does feel at the moment like everything is gathering pace and the...... the online attacks, or the online threats are just, they're increasing in their magnitude across all, all platforms, as far as I'm concerned.
- TJThomas (Tom) Johnson
Absolutely.
- CWChris Williamson
So it's, it's not just that you have this sort of below the line, underground, black hat hacker things that are going on, but also even the data which we're willingly giving away is being manipulated in more, more and more sophisticated ways. And, you know, it- it really is, it's getting ... it's getting more serious, isn't it?
- TJThomas (Tom) Johnson
It absolutely is. All these, uh, apps like, uh, the T- uh, FaceApp and the 10 Year Puberty Challenge.
- 1:01:16 – 1:04:19
The security talent gap and how to get started (legally)
- CWChris Williamson
Are you guys ... I'm going to guess the answer is yes, but you guys will be paid fairly well for your services. It will be a specialized, uh, and small group of people who have skills up to the standard that are required.
- TJThomas (Tom) Johnson
Well, the average wage for a- a qualified penetration tester with a bit of experience, uh, is between 65 and 120,000 pound a year.
- CWChris Williamson
Mm-hmm.
- TJThomas (Tom) Johnson
Um, and there is going to be a 1.8 million job deficit within the next three years. So nobody will have the skillset to do that. Um, my suggestion would be if you want a career change, do what I done, you know, quit your minimum wage job, blag yourself into university and smash it the best you possibly can. Jump in headfirst, take on every opportunity, do the best you possibly can and change your life, 'cause you can do it.
- CWChris Williamson
Tom, what an unbelievable way to end the podcast. Thank you so much for coming on, man. If, uh, if anyone who is listening wants to learn a little bit more, are there any blogs that you like or have you got anything online? Uh, um, are you on Twitter? Is- is-
- TJThomas (Tom) Johnson
Uh, no, I'm very careful on what I go on online believe it or not. (laughs)
- CWChris Williamson
I imagine- I thought- for some reason I was- I thought that you might say that.
- TJThomas (Tom) Johnson
I'm a tad paranoid, I only got a phone about a month ago. (laughs)
- CWChris Williamson
Okay. Okay. Fair enough.
- TJThomas (Tom) Johnson
Yeah, what I would suggest is if you want to learn more, uh, get yourself on Hack The Box. It is a website designed to teach hacking and you can legally hack their networks, um, they allow you to do it and have di- different capture the flag challenges.
- CWChris Williamson
Ah.
- TJThomas (Tom) Johnson
Things like that.
- CWChris Williamson
That's awesome.
- TJThomas (Tom) Johnson
You've got Over The Wire War Games, have a go at that. Um, learn Kali Linux the best you can. And if you're a student or you've got access to an academic email, get yourself on Immersive Labs, um, which was set up in conjunction with our sorta GCHQ technical sorta departments of the government. Um, and they have sorta labs that you can learn on there as well. So it's brilliant.
- CWChris Williamson
And you can have a little play around- play around in these safe environments where you can do a little bit of hacking, see if you're any good and then maybe flog your skills for 120 grand a year?
- TJThomas (Tom) Johnson
Absolutely. Absolutely.
- CWChris Williamson
Unbelievable.
- TJThomas (Tom) Johnson
Yeah. Go for it.
- CWChris Williamson
Well, and do you know what it is, I don't- I don't think that we could have done a better recruitment video if we'd tried.
- TJThomas (Tom) Johnson
(laughs)
- CWChris Williamson
Tom, uh, links to everything that we've spoken about today, uh, Naval Ravikant on Rob Reed's After On, links to Hack The Box, Over The Wire and some of the other bits and pieces we've gone through will be in the show notes below, as always. If you enjoyed this, please don't forget to give us a like and hit subscribe, it really does make me happy. Tom, man, thank you so much. I'm- I'm really excited to see what happens next. I guess we'll have to wait a couple of years until the- your non-disclosure agreement probably frees up and you can actually talk about it. But, yeah, what an awesome day. Thank you so much, man.
- TJThomas (Tom) Johnson
Fantastic. Thank you, mate.
- CWChris Williamson
Outfits. Ah, yeah. Oh, yeah. Outfits.
Episode duration: 1:04:20
Install uListen for AI-powered chat & search across the full episode — Get Full Transcript
Transcript of episode 1SkPp-kVUmQ