AI... A new dawn, or the demise of humanity ?

Blog
  • Ever since the first computer was created and made available to the world, technology has advanced at an incredible pace. From its early inception before the World Wide Web became the common platform it is today, there have been innovators. Some of those faded into obscurity before their idea even made it into the mainstream - for example, Sir Clive Sinclair’s ill fated C5 - effectively the prehistoric Sedgeway of the 80’s era that ended up in receivership after falling short of both sales forecasts and enthusiasm from the general public - mostly cited around safety, practicality, and the notoriously short battery life. Sinclair had an interest in battery powered vehicles, and whilst his initial idea seemed outlandish in the 80s, if you look at the electric cars market today, he was actually a groundbreaking pioneer.

    The technology Revolution

    The next revolution in technology was, without doubt, the World Wide Web. A creation pioneered in 1989 by Sir Tim Berners-Lee whilst working for CERN in Switzerland that made use of the earliest form of common computer language - HTML This new technology, coupled with the Mosaic Browser formed the basis of all technology communication as we know it today. The internet. With the dot com tech bubble lasting between 1995 and 2001 before finally bursting, the huge wave of interest in this new transport and communication phenomenon meant that new ideas came to life. Ideas that were previously considered inconceivable became probable, and then reality as technology gained significant ground and funding from a variety of sources. One of the earliest investors in the internet was Cisco. Despite losing almost 86% of its market share during the dot com fallout, it managed to cling on and is now responsible for providing the underpinning technology and infrastructure that makes the web as we know it today function. In a similar ilk, eBay and Amazon were early adopters of the dot com boom, and also managed to stay afloat during the crash. Amazon is the huge success story that went from simply selling books to being one of the largest technology firms in its space, and pioneering technology such as Amazon Web Services that effectively destroyed the physical data centre with its unstoppable adoption rate of organisations moving their operations to cloud based environments.

    With the rise of the internet came the rise of automation, and Artificial Intelligence. Early technological advances and revolutionary ideas arrived in the form of self serving ATM’s, analogue cell phones, credit card transaction processing (data warehouses), and improvements to home appliances all designed to make our lives easier. Whilst it’s undisputed that technology has immensely enriched our lives and allowed us to achieve feats of engineering and construction that Brunel could have only dreamed of, the technology evolution wheel now spins at an alarming rate. The mobile phone when first launched was the size of a house brick and had an antennae that made placing it in your pocket impossible unless you wore a trench coat. Newer iterations of the same technology saw analogue move to digital, and the cell phone reduce in size to that of a Mars bar.  As with all technology advances, the first generation was rapidly left behind, with 3G, then 4G being the mainstream and accepted standard (with 5G being in the final stages before release). Along with the accessibility factor in terms of mobile networks came the smartphone. An idea first pioneered in 2007 by Steve Jobs with the arrival of the iPhone 2G. This technology brand rocketed in popularity and rapidly became the most sought after technology in the world thanks to its founder’s insight. Since 2007, we’ve seen several new iPhone and iPad models surface - as of now, up to the iPhone X. 2008 saw competitor Android release its first device with version 1. Fast forward ten years and the most recent release is Oreo (8.0). The smartphone and enhanced capacity networks era made it possible to communicate in new ways that were previously inaccessible. From instant messaging to video calls on your smartphone, plus a wealth of applications designed to provide both entertainment and enhanced functionality, technology was now the at the forefront and a major component of everyday life.

    The brain’s last stand ?

    The rise of social media platforms such as Facebook and Twitter took communication to a new level - creating a playing field for technology to further embrace communication and enrich our lives in terms of how we interact with others, and the information we share on a daily basis. However, to fully understand how Artificial Intelligence made such a dramatic impact on our lives, we need to step back to 1943 when Alan Turing pioneered the Turing Test. Probably the most defining moment in Artificial Intelligence history was in 1997 when reigning chess champion Garry Kasparov played supercomputer Deep Blue - and subsequently lost. Not surprising when you consider that the IBM built machine was capable of evaluating and executing 200 million moves per second. The question was, could it cope with strategy ? The clear answer was yes. Dubbed “the brain’s last stand”, this occurrence set the inevitable path for Artificial Intelligence to scale to new heights. The US military attempted to use AI in the Cold War, although this amounted to virtually nothing. However, interest in the progress of Artificial Intelligence rose quickly, with development in this new technology being taken seriously with a range of autonomous robots. BigDog, developed by Boston Dynamics, was one of the first. Designed to operate as a robotic pack animal in terrain considered unreachable or inaccessible for standard vehicles - although it has never actually seen active service. iRobot also gained popularity and became a major player in this area. The bomb disposal device PackBot combines user control with artificial intelligence capabilities such as explosives sniffing. As of today, over 2000 of these PackBot devices have been utilised in Iraq and Afghanistan with the aim of successfully and safely tackling IED’s to prevent loss of human life.

    Never heard of Boston Dynamics ? Here’s a video that’ll give you an insight into one of their latest creations

    A similar occurrence to the Kasparov incident in 2011 saw IBM again unveil it’s latest technology (Watson) which took on the human brain again - this time in US quiz show Jeopardy. Watson was “trained” for three years to take on this challenge, and using a complex set of algorithms and machine learning, trounced the human opposition (who happened to be two of the shows smartest contestants) and stole the show. This incident quickly went viral, and placed Artificial Intelligence as a prominent technology that had advanced to the point where it proved beyond reasonable doubt to be superior to the human brain. 2014 saw the introduction of driverless vehicles that leveraged Artificial Intelligence to make decisions based on road and traffic conditions. Both Tesla and Google are major players in this area - more predominantly Tesla of late. I’ve previously written an article concerning the use of Artificial Intelligence around driverless vehicles that can be found here.

    The Facebook Experiment

    In the save year, Tim Berners-Lee himself said that machines were getting smarter, but humans were not. He also stated that computers would end up communicating with each other in their own language. Given the Facebook AI experiment conducted this year, this prediction was in fact correct. Here’s a synopsis of the discussion between two bots named Alice and Bob.

    Bob: i can i i everything else . . . . . . . . . . . . . .
    Alice: bs have zero to me to me to me to me to me to me to me to me to
    Bob: you i everything else . . . . . . . . . . . . . .
    Alice: b
    s have a ball to me to me to me to me to me to me to me
    Bob: i i can i i i everything else . . . . . . . . . . . . . .
    Alice: bs have a ball to me to me to me to me to me to me to me
    Bob: i . . . . . . . . . . . . . . . . . . .
    Alice: b
    s have zero to me to me to me to me to me to me to me to me to
    Bob: you i i i i i everything else . . . . . . . . . . . . . .
    Alice: bs have 0 to me to me to me to me to me to me to me to me to
    Bob: you i i i everything else . . . . . . . . . . . . . .
    Alice: b
    s have zero to me to me to me to me to me to me to me to me to

    Whilst this discussion became difficult to decipher from the human perspective and looked like complete gibberish (you could draw some parallel with The Chuckle Brothers on LSD) the AI learning in this experiment had actually taken the decision to communicate in a bespoke method as a means of making the stream more effective. The problem with this approach was that the bots were designed to communicate with humans, and not themselves. AI decision making isn’t something new either. Google translate actually converts unsanitized input to its own internal machine language before providing a translation. The developers at Google noticed this, but where happy for this to continue as it made the AI more effective. And now for reality. Is this considered acceptable when it’s supposed to enhance something rather than effectively exclude a human from the process ? The idea here is around interaction. There’s a lot of rumours circulating the internet as to Facebook’s decision to pull the plug. Was it out of fear, or did the scientists device to simply abandon the experiment because it didn’t produce the desired result ?

    The future of AI - and human existence ?

    A more disturbing point is that AI appears to have had control in the decision making process, and did not need a human to choose or approve any request. We’ve actually had basic AI for many years in the form of speech recognition when calling a customer service centre, or when seeking help on websites in the form of unattended bots that can answer basic questions quickly and effectively - and in the event that they cannot answer, they have the intelligence to route the question elsewhere. But what happens if you take AI to a new level where you give it control of something far more sinister like military capabilities ? Here’s a video outlining how a particular scenario concerning the usage of autonomous weapons could work if we continue down the path of ignorance. Whilst it seems like Hollywood, the potential is very real and should be taken seriously. In fact, this particular footage, whilst fiction, had been taken very seriously with names such as Elon Musk and Stephen Hawking providing strong support and backing to effectively create a ban on autonomous weapons and the use of AI in their deployment.

    Does this strike a chord with you ? Is this really how we are going to allow AI to evolve ? We’ve had unmanned drones for a while now, and whilst they are effective at providing a mechanism for surgical strike on a particular target, they are still controlled by humans that can override functionality, and ultimately decide when to execute. The real question here is just how far do we want to take AI in terms of autonomy and decision making ? Do we want AI to enrich our lives, or assume our identities thus allowing the human race to slip into oblivion ? If we allow this to happen, where does our purpose lie, and what function would humanity then provide that AI can’t ? People need to realise that as soon as we fully embrace AI and give it control over aspects of our lives, we will effectively end up working for it rather than it working for us. Is AI going to pay for your pension ? No, but it could certainly replace your existence.

    In addition, how long before that “intelligence” decides you are superfluous to requirement ? Sounds very “Hollywood” I’ll admit, but there really needs to be a clear boundary as to what the human race accepts as progress as opposed to elimination. Have I been watching too many Terminator films ? No. I live technology and fully embrace it, but replacing human way of life with machines is not the answer to the world’s problems - only the downfall. It’s already started with driverless cars, and will only get worse - if we allow it.

  • phenomlabundefined phenomlab referenced this topic on
  • And here’s an example of how AI is evolving in the sense of being exploited
    https://sudonix.org/topic/413/neural-networks-being-used-to-create-realistic-phishing-emails

  • Here’s another article that might make those not concerned by AI think again.

    https://globalnews.ca/news/9432503/chatgpt-exams-passing-mba-medical-licence-bar/

  • @phenomlab this is really interesting. I saw an article similar to this where a professor in religion gave chatgpt the bible and some other text and asked it to write a 6 page paper about a specific topic and to make it look like the professor wrote it. Three seconds later it was done and the paper it wrote was top notch and looked like it had been written by the professor.

    Looking at it from that aspect, it is scary to think a computer can do that. My other thought on it, is what if you gave the AI all the medical information that there is, including evidence based research and results from tests and research and all the different outcomes from patients world wide, what conclusion or maybe even new information it would come up with to help with disease, cancer and all that kind of stuff that could help everyone. It would probably take it a matter of seconds to figure it all out.

    I wonder if it could make diagnosing instantaneous and more accurate and maybe even better ways to fix an ailment.

    I also think that in the wrong hands it could also be very dangerous.

    It is very interesting.

  • @Madchatthew said in AI... A new dawn, or the demise of humanity ?:

    I wonder if it could make diagnosing instantaneous and more accurate and maybe even better ways to fix an ailment.

    This is an interesting take given your profession 🙂 I totally get it though - I can certainly see a hugely beneficial use case for this.

    @Madchatthew said in AI... A new dawn, or the demise of humanity ?:

    I also think that in the wrong hands it could also be very dangerous.

    They say a picture paints a thousand words…

    d6203130-99c1-4565-bb73-e79e172ed373-image.png

  • @phenomlab said in AI... A new dawn, or the demise of humanity ?:

    They say a picture paints a thousand words…

    LOL - yes, in the making LOL

  • phenomlabundefined phenomlab referenced this topic on
  • And this is certainly interesting. I came across this on Sky News this morning

    https://news.sky.com/story/godfather-of-ai-geoffrey-hinton-warns-about-advancement-of-technology-after-leaving-google-job-12871065

    Seems even someone considered the “Godfather of AI” has quit, and is now raising concerns around privacy and jobs (and we’re not talking about Steve here either 🙂 )

  • Here’s another article of interest relating to the same subject
    https://news.sky.com/story/artificial-intelligence-will-get-crazier-and-crazier-without-controls-a-leading-start-up-founder-warns-12886081

    And the quote which says it all

    “The labs themselves say this could pose an existential threat to humanity,” said Mr Mostaque

    A cause for concern? Absolutely.

  • A rare occasion where I actually agree with Elon Musk

    https://news.sky.com/story/elon-musk-says-artificial-intelligence-isnt-necessary-for-anything-12887975

    Some interesting quotes from that article

    “So just having more advanced weapons on the battlefield that can react faster than any human could is really what AI is capable of.”

    “Any future wars between advanced countries or at least countries with drone capability will be very much the drone wars.”

    When asked if AI advances the end of an empire, he replied: “I think it does. I don’t think (AI) is necessary for anything that we’re doing.”

    This is also worth watching.

    This further bolsters my view that AI needs to be regulated.

  • Google CEO Sundar Pichai admits AI dangers ‘keep me up at night’

  • This is an interesting admission from China - a country typically with a cavalier attitude to emerging tech

    https://news.sky.com/story/china-warns-over-ai-risk-as-president-xi-jinping-urges-national-security-improvements-12893557

  • And here - Boss of AI firm’s ‘worst fears’ are more worrying than creepy Senate party trick

    US politicians fear artificial intelligence (AI) technology is like a “bomb in a china shop”. And there was worrying evidence at a Senate committee on Tuesday from the industry itself that the tech could “cause significant harm”.

    https://news.sky.com/story/boss-of-ai-firms-worst-fears-are-more-worrying-than-creepy-senate-party-trick-12882348

  • An interesting argument, but with little foundation in my view

    “But many of our ingrained fears and worries also come from movies, media and books, like the AI characterisations in Ex Machina, The Terminator, and even going back to Isaac Asimov’s ideas which inspired the film I, Robot.”

    https://news.sky.com/story/terminator-and-other-sci-fi-films-blamed-for-publics-concerns-about-ai-12895427

  • phenomlabundefined phenomlab referenced this topic on
  • @phenomlab yeap, but no need to fear 😄 this might even be better for humanity, since they will have a “common enemy” to fight against, so, maybe instead of fighting with each other, they will unite.

    In general, I do not embrace anthropocentric views well… and since human greed and money will determine how this will end, we all can guess what will happen…

    so sorry to say this mates, but if there is a robot uprising, I will sell out human race hard 🤣

  • @crazycells I understand your point - albeit selling out the human race as that would include you 😕

    There’s a great video on YouTube that goes into more depth (along with the “Slaughterbots” video in the first post) that I think is well worth watching. Unfortunately, it’s over an hour long, but does go into specific detail around the concerns. My personal concern is not one of having my job replaced by a machine - more about my existence.

  • And whilst it looks very much like I’m trying to hammer home a point here, see the below. Clearly, I’m not the only one concerned at the rate of AI’s development, and the consequences if not managed properly.

    https://news.sky.com/story/ai-could-help-produce-deadly-weapons-that-kill-humans-in-two-years-time-rishi-sunaks-adviser-warns-12897366

  • @phenomlab thanks for sharing. I will watch this.

    no worries 😄 I do not have a high opinion about human race, human greed wins each time, so I always feel it will be futile to resist. we are just one of the billions of species around us. thanks to evolution, our genes make us selfish creatures, but even if there is a catastrophe, I am pretty sure there will be at least a handful of survivors to continue.

    Screen Shot 2023-06-07 at 07.24.31.png

  • @phenomlab maybe I did not understand it well, but I do not share the opinions of this article. Are we trying to prevent deadly weapons from being built or are we trying to prevent AI from being part of it 🙂

    Regulations might (and probably will) be bent by individual countries secretly. So, what will happen then?


  • 2 Votes
    1 Posts
    12 Views

    Just seen this post pop up on Sky News

    https://news.sky.com/story/elon-musks-brain-chip-firm-given-all-clear-to-recruit-for-human-trials-12965469

    He has claimed the devices are so safe he would happily use his children as test subjects.

    Is this guy completely insane? You’d seriously use your kids as Guinea Pigs in human trials?? This guy clearly has easily more money than sense, and anyone who’d put their children in danger in the name of technology “advances” should seriously question their own ethics - and I’m honestly shocked that nobody else seems to have a comment about this.

    This entire “experiment” is dangerous to say the least in my view as there is huge potential for error. However, reading the below article where a paralyzed man was able to walk again thanks to a neuro “bridge” is truly ground breaking and life changing for that individual.

    https://news.sky.com/story/paralysed-man-walks-again-thanks-to-digital-bridge-that-wirelessly-reconnects-brain-and-spinal-cord-12888128

    However, this is reputable Swiss technology at it’s finest - Switzerland’s Lausanne University Hospital, the University of Lausanne, and the Swiss Federal Institute of Technology Lausanne were all involved in this process and the implants themselves were developed by the French Atomic Energy Commission.

    Musk’s “off the cuff” remark makes the entire process sound “cavalier” in my view and the brain isn’t something that can be manipulated without dire consequences for the patient if you get it wrong.

    I daresay there are going to agreements composed by lawyers which each recipient of this technology will need to sign so that it exonerates Neuralink and it’s executives of all responsibility should anything go wrong.

    I must admit, I’m torn here (in the sense of the Swiss experiment) - part of me finds it morally wrong to interfere with the human brain like this because of the potential for irreversible damage, although the benefits are huge, obviously life changing for the recipient, and in most cases may outweigh the risk (at what level I cannot comment not being a neurosurgeon of course).

    Interested in other views - would you offer yourself as a test subject for this? If I were in a wheelchair and couldn’t move, I probably would I think, but would need assurance that such technology and it’s associated procedure is safe, which at this stage, I’m not convinced it’s a guarantee that can be given. There are of course no real guarantees with anything these days, but this is a leap of faith that once taken, cannot be reversed if it goes wrong.

  • 16 Votes
    21 Posts
    141 Views

    @crazycells said in How long before AI takes over your job?:

    sponsored content

    To me, this is the method to get yourself to the top of the list. Unfair advantage doesn’t even properly describe it.

  • 5 Votes
    10 Posts
    291 Views

    @qwinter I’ve extensive experience with Ghost, so let me know if you need any help.

  • 3 Votes
    3 Posts
    251 Views

    @downpw Yes, exactly. Sudonix is about much more than NodeBB 🙂

  • 0 Votes
    1 Posts
    163 Views

    One of the most important safety nets in IT Operations is contingency. Every migration needs a rollback plan in the event that things don’t quite go the way you’d expect, and with a limited timeline to implement a change, or in some cases, a complete migration, the rollback process is one that is an essential component. Without a plan to revert all changes back to their previous state, your migration is destined for failure from the outset. No matter how confident you are (I’ve yet to meet a project manager who doesn’t build in redundancy or rollback in one form or another) there is always going to be something you’ve missed, or a change that produces undesirable results.

    It is this seemingly innocent change that can have a domino effect on your migration - unless you have access to a replica environment, the result of the change cannot be realistically predicted. Admittedly, it’s a simple enough process to clone virtual machines to test against, but that’s of no consequence if your change relates to those conducted at hardware level. A classic example of this is a firewall migration. Whilst it would be possible to test policies to ensure their functionality meets the requirement of the business, confirming VPN links for example isn’t so straightforward - especially when you need to rely on external vendors to complete their piece of the puzzle before you can continue. Unless you’re deploying technology into a greenfield site, you do not have the luxury of testing a VPN into a production network during business hours. Based on this, you have a couple of choices

    You perform all testing off hours by switching equipment for the replacement, and perform end to end testing. Once you are satisfied everything works as it should, you put everything back the way you found it, then schedule a date for the migration. You configure the firewall using a separate subnet, VLAN, and other associated networking elements meaning the two environments run symmetrically

    But which path is the right one ? Good question. There’s no hard and fast rule to which option you go for - although option 2 is more suited to a phased migration approach whilst option 1 is more aligned to “big bang” - in other words, moving everything at the same time. Option 2 is good for testing, but may not reflect reality as you are not targeting the same configuration. As a side note, I’ve often seen situations where residual configuration from option 1 has been left behind, meaning you either land up with a conflict of sorts, or black hole routing.

    Making use of a rollback

    This is where the rollback plan bridges the gap. If you find yourself in a situation where you either run out of time, or cannot continue owing to physical, logical or external constraints, then you would need to invoke your rollback plan. It’s important to note at this stage that part of the project plan should include a point where the progress is reviewed and assessed, and if necessary, the rollback is executed. My personal preference is within around 40% of the allocated time window - all relevant personnel should reconvene and provide status updates around their areas of responsibility, and give a synopsis of any issues - and be fully prepared to elaborate on these if the need arises. If the responsible manager feels that the project is at risk of overrunning it’s started time frame, or cannot be completed within that window, he or she needs to exercise authority to invoke the rollback plan. When setting the review interval, you should also consider the amount of time required to revert all changes and perform regression testing.

    Rollback provides the ideal opportunity to put everything back how it was before you started on your journey - but it does depend on two major factors. Firstly, you need to allocate a suitable time period for the rollback to be completed within. Secondly, unless you have a list of changes that were made to hardware - inclusive of configuration, patching, and a myriad of others, how can you be sure that you’ve covered everything ?

    Time after time I see the same problem - something gets missed, and turns out to be fundamental on Monday morning when the changes haven’t been cross checked.

    So what should a contingency plan consist of ?

    One surefire way to ensure that configurations are preserved prior to making changes is to create backups of running configs - 2 minutes now can save you 2 days of troubleshooting when you can’t remember which change caused your issue.  For virtual machines, this is typically a snapshot that can be restored later should the need arise. A word to the wise though - don’t leave the machine running on snapshot for too​ long as this can rapidly deplete storage space. It’s not a simple process to recover a crashed VM that has run out of disk space.

    Keep version and change control records up to date - particularly during the migration. Any change that could negatively impact the remainder of the project should be examined and evaluated, and if necessary, removed from the scope of works (provided this is a feasible step - sometimes negating a process is enough to make a project fail)

    Document each step. I can’t stress the importance of this enough. I understand that we all want to get things done in a timely manner, but will you realistically remember all the changes you made in the order they were implemented ?
    Use differential tools to examine and easily highlight changes between two configurations. There are a number of free tools on the internet that do this. If you’re using a Windows environment, a personal favourite of mine is WinMerge. Using a diff tool can separate the wood from the trees quickly, and provides a simple overview of changes - very useful in the small hours, I can assure you.
    Working on a switch or firewall ? Learn how to use the CLI. This is often superior in terms of power and usually contains commands that are not available from the GUI. Using this approach, it’s perfectly feasible to bulk load configuration, and also back it out using the same mechanism.

    What if your rollback plan doesn’t work ? Unfortunately, there is absolutely no way to simulate a rollback during project planning, and this is often made worse by many changes being made at once to multiple systems. It’s not that the rollback doesn’t work - it’s usually always a case of settings being reverted before they should be. In most cases, this has the knock on effect of denying yourself access to a system - and it’s always in a place where there are no local support personnel to assist - at least, not immediately. For every migration I have completed over my career, I’ve always ensured that there is an alternative route to reach a remote device should the primary path become inaccessible. For firewalls, this can be a blessing - particularly as they usually permit access on the public interfaces.

    However, delete a route inadvertently and you are toast - you lose access to the firewall full stop - get out of that one. What would I do in a situation like this where the firewall is located in Asia for example, and you are in London ? Again - contingency. You can’t remove a route on a firewall if it was created automatically by the system. In this case, a VLAN or directly connected interface will create it’s own dynamic route, and should still be available. If dealing with a remote firewall, my suggestion here would be Out Of Band Management (OOBM), but not a device connected directly to the firewall itself, as this presents a security risk if not configured properly. A personal preference is a locally connected laptop in the remote location that uses either independent WiFi or a 3G / Mifi presence. Before the migration starts, establish a WebEx or GoToMeeting session (don’t forget to disable UAC here as that can shoot you in the foot), and arrange for a network cable to be plugged into switch fabric, or directly. Direct is better if you can spare the interface, as it removes potential routing issues. Just configure the NIC on the remote machine with an address in the same subnet add the interface you’re connected to, and you’re golden.

    I’ve used the above as a get out of jail free card on several occasions, and I can assure you it works.

    So what are the takeaways here ?

    The most important aspect is to be ready with a response - effectively a “plan b” when things go wrong. Simple planning in advance can save you having to book a flight, or foot the expense of a local IT support firm with no prior knowledge of your network - there’s the security aspect as well; you’d need to provide the password for the device which immediately invokes a change once the remediation is complete. In summary

    Thoroughly plan each migration and allow time for contingency steps. You may not need them, and if you don’t, then you effectively gain time that could be used elsewhere. Have an alternative way of reaching a remote device, and ensure necessary third party vendors are going to be available during your maintenance window should this be necessary. Take regular config backups of all devices. You don’t necessarily need an expensive tool for this - I actually designed a method to make this work using Linux, a TFTP server, and a custom bash script - let me know if you’d like a copy 🙂 Regularly analyse (automated diff) configuration changes between configurations. Any changes that are undocumented or previously approved are a cause for alarm and should be investigated Ensure that you have adequate documentation, and steps necessary to recover systems in the event of failure

    Any thoughts or questions ? Let me know !

  • 0 Votes
    1 Posts
    118 Views

    When you look at your servers or surrounding networks, what exactly do you see ? A work of art, perhaps ? Sadly, this is anything but the picture painted for most networks when you begin to look under the hood. What I’m alluding to here is that beauty isn’t skin deep - in the sense that neat cabling resembling art from the Sistine Chapel, tidy racks, and huge comms rooms full of flashing lights looks appealing from the eye candy perspective and probably will impress clients, but in several cases, this is the ultimate wolf in sheep’s clothing. Sounds harsh ? Of course it does, but with good intentions and reasoning. There’s not a single person responsible for servers and networks on this planet who will willingly admit that whilst his or her network looks like a masterpiece to the untrained eye, it’s a complete disaster in terms of security underneath.

    In reality, it’s quite the opposite. Organisations often purchase bleeding edge infrastructure as a means of leveraging the clear technical advantages, enhanced security, and competitive edge it provides. However, under the impressive start of the art ambience and air conditioning often lies an unwanted beast. This mostly invisible beast lives on low-hanging fruit, will be tempted to help itself at any given opportunity, and is always hungry. For those becoming slightly bewildered at this point, there really isn’t an invisible beast lurking around your network that eats fruit. But, with a poorly secured infrastructure, there might as well be. The beast being referenced here is an uninvited intruder in your network. A bad actor, threat actor, bad guy, criminal…. call it what you want (just don’t use the word hacker) can find their way inside your network by leveraging the one thing that I’ve seen time and time again in literally every organisation I ever worked for throughout my career - the default username and password. I really can’t stress the importance of changing this on new (and existing) network equipment enough, and it doesn’t stop at this either.

    Changing the default username and password is about 10% of the puzzle when it comes to security and basic protection principles. Even the most complex credentials can be bypassed completely by a vulnerability (or in some cases, a backdoor) in ageing firmware on switches, firewalls, routers, storage arrays, and a wealth of others - including printers (which incidentally make an ideal watering hole thanks to the defaults of FTP, HTTP, SNMP, and Telnet, most (if not all of) are usually always on. As cheaper printers do not have screens like their more expensive copier counterparts (the estate is reduced to make the device smaller and cheaper), any potential criminal can hide here and not be detected - often for months at a time - arguably, they could live in a copier without you being aware also. A classic example of an unknown exploit into a system was the Juniper firewall backdoor that permitted full admin access using a specific password - regardless of the one set by the owner. Whilst the Juniper exploit didn’t exactly involve a default username and password as such (although this particular exploit was hard-coded into the firmware, meaning that any “user” with the right coded password and SSH access remotely would achieve full control over the device), it did leverage the specific vulnerability in the fact that poorly configured devices could have SSH configured as accessible to 0.0.0.0/0 (essentially, the entire planet) rather than a trusted set of IP addresses - typically from an approved management network.

    We all need to get out of the mindset of taking something out of a box, plugging it into our network, and then doing nothing else - such as changing the default username and password (ideally disabling it completely and replacing it with a unique ID) or turning off access protocols that we do not want or need. The real issue here is that today’s technology standards make it simple for literally anyone to purchase something and set it up within a few minutes without considering that a simple port scan of a subnet can reveal a wealth of information to an attacker - several of these tools are equipped with a default username and password dictionary that is leveraged against the device in question if it responds to a request. Changing the default configuration instead of leaving it to chance can dramatically reduce the attack landscape in your network. Failure to do so changes “plug and play” to “ripe for picking”, and its those devices that perform seemingly “minor” functions in your network that are the easiest to exploit - and leverage in order to gain access to neighbouring ancillary services. Whilst not an immediate gateway into another device, the compromised system can easily give an attacker a good overview of what else is on the same subnet, for example.

    So how did we arrive at the low hanging fruit paradigm ?

    It’s simple enough if you consider the way that fruit can weigh down the branch to the point where it is low enough to be picked easily. A poorly secured network contains many vulnerabilities that can be leveraged and exploited very easily without the need for much effort on the part of an attacker. It’s almost like a horse grazing in a field next to an orchard where the apples hang over the fence. It’s easily picked, often overlooked, and gone in seconds. When this term is used in information security, a common parallel is the path of least resistance. For example, a pickpocket can acquire your wallet without you even being aware, and this requires a high degree of skill in order to evade detection yet still achieve the primary objective. On the other hand, someone strolling down the street with an expensive camera hanging over their shoulder is a classic example of the low hanging fruit synopsis in the sense that this theft is based on an opportunity that wouldn’t require much effort - yet with a high yield. Here’s an example of how that very scenario could well play out.

    Now, as much as we’d all like to handle cyber crime in this way, we can’t. It’s illegal 🙂

    What isn’t illegal is prevention. 80% of security is based on best practice. Admittedly, there is a fair argument as to what exactly is classed as “best” these days, although it’s a relatively well known fact that patching the Windows operating system for example is one of the best ways to stamp out a vulnerability - but only for that system that it is designed to protect against. Windows is just the tip of the iceberg when it comes to vulnerabilities - it’s not just operating systems that suffer, but applications, too. You could take a Windows based IIS server, harden it in terms of permitted protocols and services, plus install all of the available patches - yet have an outdated version of WordPress running (see here for some tips on how to reduce that threat), or often even worse, outdated plugins that allow remote code execution. The low hanging fruit problem becomes even more obvious when you consider breaches such as the well-publicised Mossack Fonseca (“Panama Papers”). What became clear after an investigation is that the attackers in this case leveraged vulnerabilities in the firm’s WordPress and Joomla public facing installations - this in fact led to them being able to exploit an equally vulnerable mail server by brute-forcing it.

    So what should you do ? The answer is simple. It’s harvest time.

    If there is no low-hanging fruit to pick, life becomes that much more difficult for any attacker looking for a quick “win”. Unless determined, it’s unlikely that your average attacker is going to spend a significant amount of time on a target (unless it’s Fort Knox - then you’ve have to question the sophistication) then walk away empty handed with nothing to show for the effort. To this end, below are my top recommendations. They are not new, non-exhaustive, and certainly not rocket science - yet they are surprisingly missing from the “security 101” perspective in several organisations.

    Change the default username and password on ALL infrastructure. It doesn’t matter if it’s not publicly accessible - this is irrelevant when you consider the level of threats that have their origins from the inside. If you do have to keep the default username (in other words, it can’t be disabled), set the lowest possible access permissions, and configure a strong password. Close all windows - in this case, lock down protocols and ports that are not essential - and if you really do need them open, ensure that they are restricted Deploy MFA (or at least 2FA) to all public facing systems and those that contain sensitive or personally identifiable information Deploy adequate monitoring and logging techniques, using a sane level of retention. Without any way of forensic examination, any bad actor can be in and out of your network well before you even realise a breach may have taken place. The only real difference is that without decent logging, you have no way of confirming or even worse, quantifying your suspicion. This can spell disaster in regulated industries. Don’t shoot yourself in the foot. Ensure all Windows servers and PC’s are up to date with the latest patches. The same applies to Linux and MAC systems - despite the hype, they are vulnerable to an extent (but not in the same way as Windows), although attacks are notoriously more difficult to deploy and would need to be in the form of a rootkit to work properly Do not let routers, firewalls, switches, etc “slip” in terms of firmware updates. Keep yourself and your team regularly informed and updated around the latest vulnerabilities, assess their impact, and most importantly, plan an update review. Not upgrading firmware on critical infrastructure can have a dramatic effect on your overall security. Lock down USB ports, CD/DVD drives, and do not permit access to file sharing, social media, or web based email. This has been an industry standard for years, but you’d be surprised at just how many organisations still have these open and yet, do not consider this a risk. Reduce the attack vector by segmenting your network using VLANS. For example, the sales VLAN does not need to (and shouldn’t need to) connect directly to accounting etc. In this case, a ransomware or malware outbreak in sales would not traverse to other VLANS, therefore, restricting the spread. A flat network is simple to manage, but a level playing field for an attacker to compromise if all the assets are in the same space. Don’t use an account with admin rights to perform your daily duties. There’s no prizes for guessing the level of potential damage this can cause if your account is compromised, or you land up with malware on your PC Educate and phish your users on a continual basis. They are the gateway directly into your network, and bypassing them is surprisingly easy. You only have to look at the success of phishing campaigns to realise that they are (and always will be) the weakest link in your network. Devise a consistent security and risk review framework. Conducting periodic security reviews is always a good move, and you’d be surprised at just what is lurking around on your network without your knowledge. There needn’t be a huge budget for this. There are a number of open source projects and platforms that make this process simple in terms of identification, but you’ll still need to complete the “grunt” work in terms of remediation. I am currently authoring a framework that will be open source, and will share this with the community once it is completed. Conduct regular governance and due diligence on vendors - particularly those that handle information considered sensitive (think GDPR). If their network is breached, any information they hold around your network and associated users is also at risk. Identify weak or potential risk areas within your network. Engage with business leaders and management to raise awareness around best practice, and information security. Perform breach simulation, and engage senior management in this exercise. As they are the fundamental core of the business function, they also need to understand the risk, and more importantly, the decisions and communication that is inevitable post breach.

    There is no silver bullet when it comes to protecting your network, information, and reputation. However, the list above will form the basis of a solid framework.

    Let’s not be complacent - let’s be compliant.

  • 1 Votes
    1 Posts
    243 Views

    What would happen if a cyber criminal attempted to scam a security professional ? Well, some time ago, this happened to me. Like everyone, I certainly receive my fair share of junk email, scams, and pretty much everything else that the internet these days tends to throw at you. For the most part, each one of these “attacks” is ignored. However, one caught my eye after only the first paragraph. Not only was the format used absurd, but the supposedly “formal tone” was nothing short of a complete joke. Unfortunately, there really is no “TL;DR” synopsis for this particular event.

    Scrolling to the bottom of the article is of course up to you, but you’ll not only miss out on key information - you’ll also miss out on my sarcasm 🤣

    Admittedly, this “scam” sounds far fetched. But, believe it or not, this particular campaign has a high success rate (and, all content in this article actually happened). If this were not the case, would a potential criminal go to such lengths to impersonate and engage ? No. They rely on that one human trait known as trust. Trust which in this case is readily exploited. I promise that this article will be worth your while reading. Ready ? Buckle up. its going to be an interesting ride. During the journey, I’ll highlight the warning signs and provide an explanation into each. Let’s start.

    Day 1

    Out of the blue, I was contacted via email by someone calling themselves “Andrew Walter” - purportedly an employee at Bank of America. The first immediate sign that something is not quite all it seems here is that the email address used is in fact from the contact form on this site. What’s significant about that ? Well, there are a variety of techniques used by cyber criminals to gain access to legitimate email addresses. One known and widely used technique is the scraping of email addresses from websites and social media - in fact, the most notable is LinkedIn.

    Despite its age and somewhat basic approach, it still works very well. Why didn’t I secure it ? Simple. The contact form on this site also doubles as a honeypot. You’d be surprised what lands in here - as this “campaign” did. For the record, Phenomlab does not retain any information from this contact form. The initial text in the email might have been relatively convincing if it hadn’t contained a ”glow in the dark” grammatical error within the first line. What I’m alluding to here is that the email may as well have arrived complete with sirens and flashing lights. Here’s a snapshot

    Dear Mark Cutting. “I added you to my professional network in order to share a confidential proposal with you please contact me on my private email: andrewwalter411@gmail.com for briefing on proposal since i can not send attachment via linkedin”.

    Actually, you didn’t. I received no such request. Let’s have a look at the initial baiting technique. Who writes an email using the full name of a person without addressing them in the business (or even personal for that fact) sense ? In addition, why would you wrap what you want to say in quotes ? Finally, “I can not send attachment via LinkedIn” - actually, I received two from trusted sources in the same platform a day earlier. This email was so cringe worthy, I thought it rude to not reply ?

    Andrew, Can I ask what this is in relation to please ? Thanks

    That’s the hook that a scammer needs. After this, the response is a lot more detailed as the criminal plays out the story. I’m going to highlight the areas of interest here as I go, and have attached the full text in order to keep this article sane.

    I will start by saying thanks for your response…How is your family doing? I hope okay.

    Good start. Make it look like you know me personally and commence with the pleasantries - even though you in fact know nothing about me, and, in reality, couldn’t care less.

    My proposal is very important to me so please I want you to take the content of this mail very serious. All I want is an honest business transaction between us.

    This is anything but honest

    Day 2

    First of all, I will start by introducing myself. My name is Andrew Walter, I am currently working with Bank of America. I have been working here for 17 years now, and I have a good working record with my bank.

    That’s strange. According to the array of fake Andrew Walter (Bank of America) LinkedIn profiles, you’ve been there for 12 years. Did you step into a time machine and not tell anyone ? Perhaps you banged your head and lost 5 years in the process. What’s more than likely is that like most bad liars, you’ve lost track of what you told one person as oppose to the next. At least you tried to enforce a bit of trust with your statement around “I have a good working record with my bank”.
    1614967980-136791-linkedinpng.webp1614967988-257399-linkedin2png.webp

    I am also the personal accountant to Engineer (Lex Cutting ), a foreign contractor who has an investment account with my bank with a huge sum of money in it.

    Note the misplaced bracket here, and also note, that there is no “Lex Cutting” in my family tree. Am I a grammar snob ? No, but I expect a “business transaction” (if you can call it that) to at least not contain basic grammatical errors.

    My late client was a chemical consultant contractor with Royal Dutch Shell until his death in a fatal car accident while at France on sabbatical with his entire family. The accident unfortunately took the lives of the family members comprising of himself, his wife and two kids in the summer of 2007 may their soul rest in perfect peace.

    He banked with us here at Bank of America and had a very huge sum of money in his account which has still yet not been claimed by anybody as there was no living will in place when he died.

    “May their soul rest in perfect peace” and “A very huge sum of money” - instant alarm bells owing to the poor grammar. If you’re working under the pretence of being an educated individual employed by a tier 1 bank, you’re not doing a very good job.

    The amount of money involved here is about $15,812,664 (Fifteen Million, Eight Hundred and Twelve Thousand six hundred and sixty four US Dollars.) in account with indefinite interest.

    Holy s***, I’ve won the lottery !! Contain yourself man, and remember, its a fake ! Ok, composure resumed.

    Since the death of my client; my bank and I have made several inquiries to his embassy to locate any of his extended family members or relatives but this has proven unsuccessful. I came to know about you in my search for a person who shares the same last name as my late client.

    Yes - I and thousands of others no doubt. How lucky I’ve been selected for this “unique opportunity”.

    employed the services of LinkedIn search solely for this purpose as I feel it would not have been the last wishes of my late client for his whole life work to be transferred to a government (Es cheat) he had always complained of their unfavorable public monetary policies, taxes and so on while he was alive.

    Ok, so let me get this straight. You’ve trawled LinkedIn looking for “beneficiaries” when there are other far more orthodox and reliable channels to obtain this information. I can smell the sweat and toil of poorly conducted fraud here. Oh, and by the way, “Es cheat” is actually one word (ESCHEAT).

    My bank has issued me several notices to provide the next of kin or the account risk been es cheat within the next 10 official working days. The last notice for claim came to my desk last week. I am contacting you to assist me in repatriating the funds left behind before they are declared un-serviced by my bank. I am seeking your consent to present you as the next of kin of my late client since you share and bear the same last name.

    As such, the proceeds of the account can be paid to you as soon as you contact my bank and apply for the funds to be released to you as the next of kin. If we can be of one accord, I see no reason why we would not succeed. We both have to act swiftly on this matter in other to beat the deadline es cheat date.Please get back to me immediately for us to proceed.

    Wait a minute. If I’m the sole beneficiary, why do you want half ? Sounds like easy money to me. And the usage of “one accord” is somewhat “odd”.

    I am after the success of this transaction with your full co-operation. All I require is your honesty and full co-operation to enable us see this cool deal go through.

    I bet you are. “Cool deal” ? I thought I was taking to a professional here, not a school kid. Seems like our man has let his guard down for a split second and now his “Inna Gangsta” is shining through.

    I guarantee you that this will be executed under a legitimate arrangement that will protect you and me from breaching USA laws. I want to also inform you that I am a very religious person and I cannot tell a lie because of my strong believes; I would expect the same from you.

    Oh please, do me a favour. Pull the other one - its got bells on.

    I will attach a copy of my international passport in my next mail for authenticity so we have equal ground to trust each other. If you are interested in my proposal I will send you more information directing you on further procedure on how we can claim the money in the account successfully. If this proposal is alright by you then kindly get back to me.

    “Alright by you” - there’s that superb [sic] usage of business language again. This guy is awesome.

    The content of this mail should be treated with utmost confidentiality and a quick response from you will be highly appreciated. However, if you are not interested in this proposal, please accept my apologies for sending you the message and kindly delete message, I promised that you will never hear from me. I anticipate your co-operation.

    Of course. You wouldn’t want local law enforcement or the ”feds” knocking at your door now, would you ?

    Day 3

    This by now is so hilarious that I just had to respond.

    Hi. This sounds great. What would the next steps be ? Eagerly awaiting your response.

    And, without delay, here’s the response

    Dear Mark Cutting. I thank you for responding to my mail, I want to stress again that this transaction is very legitimate and there is no risk involved as I am the personal accountant to Late Engineer (Lex Cutting ) anything I say concerning this will be followed by the bank Executives.

    I bet. Actually, I’m struggling to follow your appallingly bad grammar here, but I expect you have your “very legitimate” reasons.

    However, before we can proceed further, I want you to assure me that you will be honest during the transaction and as soon as the funds is transferred to you we can meet in person and share money peacefully. You should understand that this transaction can be successful if we work together and as soon as I give you all legal procedure you will receive the funds from my bank, so I really need your assurance before we shall proceed.

    Wait - you want me to be honest ? Who’s scamming who here ?? What a complete scumbag.

    As I read your email I am very convinced with you and serious about this arrangement process as such, I would want you to take this serious too. My personal instinct directed me to contact you and I hope it was not a wrong thing to do.I shall direct you on the process of the claim; we shall start by sending a formal application to this effect. I will send you the text for the claims and transfer application to this effect. Thereafter, the bank will request of you the relevant back up documents to your claim and application according to the demand of our probate law for transfer of funds.

    Once you have provided the Bank with their demands, they would now be under legal obligation to transfer the funds to bank account provided by you. As part of the procedure of the claims, the documents that will be required from you will have to be acquired through legal procedures as the application of claim will be complimented with a legal award we shall have to seek from our law Court here. Be assured that the procedures to be adopted in effecting the transfer in your favor will be official and legal which will protect us from any breach of the law, We have the next 10 official working days.

    Right. Sounds fairly “straightforward”.

    Note: High confidentiality is required at all times. Do not tell anyone about this because, it might be unsafe for both of us. It would be safer for us to communicate by email for now as we have the trust. I hope you see reason with my decision on us talking by mail for now. As soon as the money has been transferred to your account, I will look for a country of our choice where we can see in person and subsequently share the funds in the ratio as discussed earlier.

    I can assure you it won’t be unsafe for me, but it probably is for you -“…now we have the trust”. Note, that the scammer gains confidence here, and starts making some fairly basic mistakes.

    Above all, I personally count on God to facilitate our plan and understanding, to produce not just success but also peaceful sharing of the funds at the end of the day and a wealthy family business relationship between us. I also pray for establishment of cordial relationship between us, God being our helper.

    I agree - you’re definitely going to need all the help you can get here. You’re not getting anything from me, so divine intervention is probably the only thing you have left.

    As soon as I hear from you and receive your assurance, I will send you the Text of Application for you to contact my bank for the release of the funds in the account of (Lex Nicholl) to your account as his next of kin.

    Hold it right there ! Who is Lex** “Nicholl”** ? Major alarm bells here. Looks like this guy has his wires crossed or didn’t get good morning injection of caffeine. This is a glaring oversight and I’m guessing all those lovingly created campaigns have a similar fault.

    would advice that you follow all the steps and procedures which I will give you so that we can get to the end of this transaction quickly. I need you to send a copy of your international passport to me and I will send mine as soon as I receive your reply indicating understanding from both of us.

    Of course. You need my passport. How undeniably stupid of me to think that you could complete this “transaction” without stealing the holy grail of personally identifiable documents in the process and using it like the gift that keeps giving for your other criminal campaigns (I sincerely hope they are better than this one).

    Day 4

    Time to turn up the heat a bit

    Hi. Can you send me the claims transfer forms for review ? Thanks

    This guy is like a dog on heat and he’s well and truly bitten this

    Dear Mark Cutting. I hope you and your family are well am so sorry for my late response as i read your email I was convinced, and I want you to understand that I need proper confirmation as I states below to be more in assurance of doing this transaction with you. The documents that will be required from us will have to be acquired through legal procedures as I explained, the application of claim will be complimented with a legal back up confirming this as a legitimate transaction, I have the account details with all access codes and will give it to you once it is required by the bank, also with me here all approvals will be provided and the transfer released to you.

    We are going to keep our communication on email for now to ensure that we are under absolute security due to high level call interception here in United States I would like you to see it with me that security is very necessary we have to be on email or text messages until the transaction is completed and I will visit you to implement our sharing.

    Yes, I agree that security is “very necessary” and also appreciate you do not want roughing up by “the feds” anytime soon. Let’s keep the communication on email so I don’t start to question who you are ? A quick side note here - if you want a secure channel, email is completely the opposite unless its been encrypted - which this hasn’t, and could be subject to eavesdropping. And, as a way of putting my mind at rest, here’s a lovely fake passport for your viewing pleasure. To the untrained eye, this could look convincing, but it a fake. One of the key identifiers here are the “wavy lines” over the picture. This is in fact a security watermark, and is unique for each passport issued. The lines will never repeat each other - if you look carefully at the below, the lines do in fact repeat.
    1614968131-783791-passport-fakepng.webp
    Below is an actual fake passport that was used in a scam a number of years ago. You’ll notice that this one is slightly less complex as it has the watermark missing, but is still fake, nonetheless.
    1614968502-542440-fake-passport-examplejpg.webp

    The transfer in your favor will be official and legal which will protect us from any breach of the law. Whatever the cost of his transaction will be, is going to be on both of us which I believe that you will not let me handle all the process alone.

    Of course not. You wouldn’t want to have to share any of the spoils, would you ? And just like any other “business transaction” you don’t want to be spending any of your money unnecessarily. Interesting that he’s actually used the US English “favor” rather than the UK English of “favour”. Pity he’s not been so diligent elsewhere. I know…let’s try and spend mine.

    I will give you the text application letter of the transfer request for our ledger department and also details on the way forward with the transaction once you have agreed with the following

    Are you ready to maintain the high level of confidentiality required for the successful conclusion of this transaction?

    Are you promising me that your account can be able to carry a transaction of such magnitude without any problem

    Are you willing to accept 50% for your participation without any problems in collecting my share from you?

    “Yes, yes, yes !” Let’s do this thing, and I’ll also throw in a portable radio to make the deal even more “appealing”.

    I will need your help in directing me and investing part of my share in your country the investment will be under your control until I am able to take over or it can be a joint venture depending on your decision. as soon as i receive a copy of your passport or id document and i as well have attached a copy of my passport for you to see whom you are working with.

    Please reply as soon as possible if you in understanding with me so that we can proceed with the bank with text application.

    Day 5

    Now this is getting interesting. What this really means is that once I have your bank details, I won’t be making a deposit - only a withdrawal (from my account, of course). Time to contact the Bank of America - this guy is an absolute riot (anagram of idiot) and yes, I can’t spell either, or count.

    Dear Sirs, I write with reference to what I believe to be a 419 Nigerian scam, sent to my email address. I am a security expert by trade, and wish to report this to yourselves. I believe the “sender” is impersonating one of your employees. I have also enclosed a scanned PDF file of the “passport”, which I also believe to be fake. I’m currently entertaining this individual as a way of reeling him in so I can report him to the necessary authorities.

    Clearly, I have no intention of supplying any sensitive information, including my passport. Whilst I expect that you receive many emails of this nature, I would like confirmation that the enclosed photo in the passport is not in fact a Bank of America employee

    Sadly, absolutely no response from Bank of America. I expect that they receive thousands of emails like this on a regular basis. Oh well, onward and upward. Let’s not keep our friend waiting.

    Hi Mark , Thank you for your email, and understanding, we do not have much time to complete this transaction to avoid reaching the es-cheat date.i will start the preparation of the application text which will be submitted to the bank as official application to cover the estate by the family member of Late Mr. Lex Cutting.

    I will send it to you for review by tomorrow. As a side note, there’s that misplaced capital letter

    Well now, that’s more like it ! Now we’re best friends forever, we can lower our guard a bit and revert to informal language (well, formal in the sense that our author is suffering from capital letter displacement). Perhaps we caused a bit of suspicion in our last messages and want to be a bit more convincing ? I’m game if you are buddy. Let’s make this a bit more interesting.

    Hi Andrew, Thanks for the email. I’ve just moved house, and things are in a bit of a mess, so I cannot place my passport for a few days until I’ve finished unpacking - hopefully, this doesn’t cause you any problems. I can answer “yes” to all the questions below.

    In the meantime, to speed up the process, is there any way we can proceed whilst I attempt to find my passport ?

    Thanks

    Well, look at me ! I know exactly where my passport is and I haven’t moved house - we need a bit of time here to do some further digging, so I’m throwing him off the scent for a few days whilst I perform some background investigation and analysis. I let this go on for 6 days before responding - note, that previously, “Andrew” had warned me we only had 10 days to nail this “cool deal”.

    We’ve since passed that landmark, but interestingly, he’s not that worried it seems. Admittedly, at this point I thought of sending a copy of Jason Bourne’s passport which are readily available for download via a quick Google - http://www.indyprops.com/pp-bournepass.htm. However, despite my assumption that this person I’m dealing with is stupid, I don’t think there’s many people on this planet who haven’t heard of Jason Bourne or seen at least one movie from the franchise.

    Based on this simple conclusion, its not a wise move in my view as it means ending the story here (unless this guy has been living under a rock)…. and there’s so much more to tell yet ! Therefore, we’ll need to take another route. Let’s increase the stakes. Note that by this point, we’re up to day 5, and we only had 10 days to complete this “cool deal”.

    Its now day 11 after I’ve kept him waiting for 6 days intentionally.

    Day 11

    Hi Andrew, Sorry for the delay. I finally found my passport, and have scanned a copy. However, I’ve read that email isn’t secure, so I can either FedEx a copy to you (I’ll need an address of course), or I can provide a secure link for you to download a password protected zip file. I’ll email you the password for that under separate cover. Would this be ok ? Keen to get things moving. Thanks

    I can almost hear the cogs in motion as my best friend formulates a response. A spanner in the works and probably not on his “canned response” sheet. This guy now needs to up his game to stay in the running.

    Hi mark. I hope you and your family are well? thank you so much for your mail please scan and send the copy of your international passport to this email (andrewwalter166@gmail.com) will can communicate much better even while i’m right in my work place i can reply over there anytime. as soon i receive your reply we will be proceeding with the text of application.

    I will be waiting to hear from you.

    Yes, I bet you will. This is the response I expected (note the “new” email address highlighted in yellow above - why change this now ? Keep reading) - if I then dropped out afterwards, this guy would still have a copy of my genuine passport, and could (and undoubtedly would) use this to commit other types of fraudulent activity.

    Essentially, its all about the money, so if the primary campaign fails, there is a good chance the second one will succeed, which is why the passport is requested so early to avoid over investment in terms of time.

    Hi Andrew, I really don’t want to send my passport by email. Can you give me an address of where it can be sent (postal) or let me know if you’d be ok downloading the copy needed from a link I will provide ? Thanks

    “Hang him on a hook and let me play with him”
    1614968549-147228-hhoahjpg.webp
    I’m so bad. Let’s see how much he wants this. Pushing for the postal address risks blowing the (supposedly carefully planned) cover and exposing him. He can’t exactly give me an address in Africa now, can he ? I’ve already preempted this and laid the foundations for a honeypot trap. I need to explain myself a bit here for those reading this and scratching their heads with images of Winnie the Pooh and a honey jar, so bear with me.

    A honeypot is a computer system or landing page that is set up to act as a decoy to lure fraudsters and cyber criminals - its essential function is to detect, deflect or study attempts to gain unauthorized access to information systems that are not for public use. At the heart of this honeypot is a system that is capable of obtaining a wealth of information about the accessing user in terms of IP address, geographic location, and a whole variety of data that would allow the recipient to piece together a trail of breadcrumbs. Any seasoned cyber criminal knows about the existence of such technology (its not exactly new) and would typically use a TOR browser to connect to any links provided by the victim in order to avoid detection.

    The TOR network is a complex array of secured computer systems acting as “nodes” that traverse the internet using a variety of encryption mechanisms and connection masking, allowing the user to hide behind a number of random proxies that make it look as though he or she is accessing from a completely different geographical location. The TOR network was originally intended for use by the US navy, but found its way out and became the favourite watering hole for many a cyber criminal - and today, known as either the deep web, or worse, the dark web. Ok, that’s enough history and boring technical terms. Let’s get back on track. Essentially, I’ve created a hidden honeypot on this site and the only two people who have this link are myself, and our scammer friend. The page cannot be indexed or crawled by Google either. Time to up the stakes

    Hi Andrew, Any update to this please ? Thanks

    Day 12

    No response. Perhaps I’ve pushed this a little too far. Let’s see

    Hi Andrew, I’m concerned that I haven’t heard from you and don’t want to miss out on this amazing opportunity. Can you let me know what we need to do next please ? Thanks

    I honestly thought that he wouldn’t reply, but he did.

    Dear Mark Cutting. Hope all is fine with you and the family? i am writing to know if you are still interested with this transaction i need a copy of your international passport in other to know whom i’m working with for more verification as soon you send it down here

    Now, when I went to school, the UK was across from America and not down - hence the term “across the pond”. Did I miss something here ? A figure of speech perhaps, but more likely a slip of the tongue. Looking at a map “down here” would indicate south, surely ?

    we will be proceeding with the text of application to contact my bank for funds relic please update me as soon as possible.

    And here we have another schoolboy error. This guy thinks he can relax now he’s done his chore. Not only is the text clearly copied and pasted (with the formatting intact so he first line doesn’t match the rest in terms of font size), but much worse is the fact that he’s now using a different email address altogether and hasn’t even made any attempts to hide this. Clearly, he’s got a lot going on, and there are undoubtedly hundreds of “Andrew Walter” doppelgangers lurking in the shadows like something out of Michael Jackson’s “Thriller”.

    To understand this complete failure, let’s take a closer look - perhaps he’s got some sort of “Salesforce(esque)” campaign on the go where willing participants are directed to another email address for easy reference (milking)! The email address we started with was “andrewwalter411@gmail.com” which in itself isn’t very convincing. Now we’ve suddenly switched to “andrewwalter166@gmail.com” and also lazy again with our grammar as “Andrew Walter” is now “andrew walter”.
    1614968634-496024-emails.webp
    I suppose I could send him a Starbucks voucher so he can get a strong coffee and wake up, but, this is his gig, so I’ll let him play his hand.

    Hi Andrew, As I previously mentioned, I won’t send my passport via email because I was told it wasn’t secure. Instead, I’ll provide a link to a secure website where it can be downloaded as a zip file. I’ll also provide the password for the zip file so you can extract it. I’ll get this over to you today. Thanks

    Now we’re “upping the ante” a bit. Not only do we respond to the original email, but also to the new one with the same message above. I’m relatively sure at this point that our friend isn’t exactly an experienced fraudster, and probably won’t even notice his own mistake. Wait for a bit……. then send the link. Note that the link itself has been redacted for obvious reasons and is not the original.

    Dear Andrew, I’ve scanned a copy of my passport to PDF and placed it in a password protected ZIP file. It can be downloaded using the link below. https://[redacted]/KCXXu4MN8G6FZqFt4Mb7hQfRZXmHA3Fn/securedownload/ Let me know as soon as you’ve downloaded the ZIP file, and I’ll send you the password in a separate email. Thanks

    I wasn’t really expecting this guy to bite if I’m being honest, but never say die - he’s just fallen straight into the honeypot (or should I say, “boiling pot”)

    Hi, the link is infected i can not open it my system refused to run the link. send it via pdf which i can view before download or jpg.

    Actually “Andrew”, the link **isn’t **infected. I understand your frustration though, as its very annoying having your time wasted by a moronic idiot who seems to lack the ability to string even basic sentences together…… Alright - that’s enough of that. The thing is “Andrew”, you didn’t follow my instructions. Not that this really matters at the moment anyway as I have got what I came for. The string on the carrot has just been made shorter. I know at this point, you can almost taste it, but I’m not finished with you just yet.

    Hi Andrew, The link works fine on my PC. its a password protected ZIP file created by 7Zip. If you use this to extract, you’ll need to enter the password to extract the PDF which I’ll send you under separate cover. Regds

    He’s in for a bit of a surprise when he gets around to opening that Zip file. There’s a PDF there all right, but it’s certainly not my passport. In fact, “Andrew” has had three attempts at downloading that file
    1614968689-559410-file-downloadpng.webp
    According to the honeypot, it would appear that he’s operating out of Randburg (Johannesburg, South Africa) - a very well known fraud hotspot.
    1614968849-529265-locationpng.webp
    The GEO information is provided courtesy of https://db-ip.com/41.113.125.214

    If those coordinates are accurate, then the local law enforcement aren’t too far away. Have a look below
    1614968903-340115-policepng.webp
    In fact, about 12 miles away (dependant on exact location of course, which the local ISP can provide when requested by law enforcement agencies)
    1614969237-763652-directions1.webp

    Day 13

    The next steps here are quite obvious. Pass it onto the local authorities to investigate, with a copy of all material received thus far

    Dear Sirs, I write with reference to an incident where a scammer in your location has trawled LinkedIn and obtained my address with a view to commit coercion and fraudulent activity. The IP address that this fraud attempt has originated from is https://db-ip.com/41.113.125.214. I have a complete record of all activity, plus a copy of what I believe to be a stolen passport.

    I am a security professional by trade, and wish to report this as criminal activity. I have a complete evidence chain of emails relating to this particular event - the incumbent has requested a copy of my passport (which for obvious reasons I will not be providing), and no doubt will also attempt to acquire my bank details. This person is posing as “Andrew Walter” from Bank of America - there are several fake profiles on LinkedIn relating to this individual. I am also aware that local law enforcement can request the physically connected location for this address - you should find its about 12 miles away from your location.

    I have obtained this fraudster’s IP address via a honeypot on my website, which I purposely setup to extract this information. I would appreciate your cooperation in this individual’s apprehension, as it would appear that the same person is responsible for a number of similar campaigns designed to extract funds from others. I am based in the UK, but can be free to discuss as you deem fit. I have enclosed copies of all emails received so far, plus an example of the LinkedIn profiles which I believe are fake. Mark Cutting

    And the below read receipt shows that this email has been read (well, opened, at least)

    Your message was read on 16 May 2018 10:32:48 AM UTC. Final-recipient: RFC822; T0023694@saps.gov.za Disposition: automatic-action/MDN-sent-automatically; displayed X-MSExch-Correlation-Key: c1tMJuEijE6r4WJRtMhQlw== X-Display-Name: GPS:Randburg SC Admin

    its at this point where things become much clearer. This guy really hasn’t done his homework. He’s been conversing with me outside of US time zones (well, Johannesburg is only currently 1 hour ahead of the UK after all) which can only mean he either has severe insomnia, or isn’t actually based in the USA. I wonder which one it could be ? Perhaps he should see a doctor and get some pills for that…. 🙂 I’ve since sent “Andrew” another email, but unfortunately, he hasn’t replied. I guess he’s “busy” with his next victim.

    Hi Andrew,

    I’m a bit concerned I’ve not heard from you, and with the deadline approaching, I really do not want to miss out. Can you let me know if you were able to open the zip file with 7zip as I previously mentioned ?

    When you try to extract it, you’ll need a password which I’ll provide to you once you confirm you’re able to open.

    Please keep me updated.

    Thanks

    The ironic thing here is that “Andrew” in fact already has the password for that zip file I sent him ! If he’s the hotshot he makes out to be, then I’m sure he’ll work it out. In the meantime, I’m guessing you all want to know what that zip file contained ? Well, I did say it was a PDF, but its not my passport. Here you go.
    1614969001-333126-pdf1png.webp

    Conclusion

    Sadly, there’s been no response to the email I sent to SAPS (South African Police Services). Oh well. They have all the evidence they need, although in fact, no actual “fraud” has been committed. That effectively means that “scoping out” a potential victim and attempting to reel them in isn’t actually an offence. Although identity impersonation certainly is and I’d be surprised if they were not interested in this.

    So there you have it - a walk-through of what to look for in these types of scam. Here’s the highlights

    No official institution like the Bank of America is going to allow its employees to conduct business over a GMAIL account. In all honesty, faking the bankofamerica.com domain would have been much more convincing, and wouldn’t have taken much effort either. After a quick iteration of the real name, I found the below If an email supposedly comes from the US, then why are all emails being sent outside of their working hours ? Any transaction of this sort would never be conducted over email anyway - for this amount (if this were indeed real), it would have to be completed face-to-face in the presence of bank officials, lawyers, compliance, and a whole raft of others. No institution is going to request a copy of any identifiable details (passport, bank accounts, etc.) over email. Poor grammar is an immediate warning sign. You need at least a decent grade in English if you are going to pretend to be someone you’re not Bad spelling is another. There are so many errors here and it makes any campaign stand up and shout “hey, I’m fake !”

    Hope you enjoyed this somewhat absurd journey.

    Keep safe out there, folks.

  • 0 Votes
    1 Posts
    144 Views

    I’m excited to announce that a new blog section has been added 😛 The blog is actually using Ghost and not NodeBB, and also sits on it’s own subdomain of https://content.sudonix.com (if you ever fancy hitting it directly).

    We’ve moved all the blog articles out of the existing category here, and migrated them to the Ghost platform. However, you can still comment on these articles just like they were part of the root system. If you pick a blog article whilst logged in

    7e61c35b-2304-4c06-bda2-34da52252e1a-image.png

    Then choose the blog article you want to read

    7ca5089e-cf7e-4050-b951-5426fd1c6ec3-image.png

    Once opened, you’ll see a short synopsis of the article

    1bc086b4-5968-4e81-bc47-70de263b2275-image.png

    Click the link to read the rest of the post. Scroll down to the bottom, and you’ll see a space where you can provide your comments ! Take the time to read the articles, and provide your own feedback - I’d love to hear it.

    3f712e7c-475d-42d4-a5ca-b4becff6cc2e-image.png

    The blog component is not quite finished yet - it needs some polish, and there’s a few bugs scattered here and there, but these will only manifest themselves if a certain sequence of events is met.