It’s Not the Technology That Pwns You, It’s the Trickery
Online scam protection starts with understanding the trick, not the technology. Alan Shimel welcomes Frank Riccardi, a cybersecurity and privacy expert. His new book is CTRL+ALT+PWN: The Hacker’s Playbook (And How to Beat It). Furthermore, Frank wrote the book for everyday people who do not know much about hacking.
From compliance to cybersecurity
Frank is a lawyer and a retired chief compliance and privacy officer from large healthcare systems. In addition, every compliance role he took came with privacy, HIPAA and breach response attached. Consequently, he moved from the legal side into cybersecurity and never looked back. After retiring in 2021, he wrote Mobilizing the C-Suite: Waging War Against Cyberattacks for board members and executives.
The trickery behind the technology
Frank says the technology is almost secondary to the trick. QR codes, for example, are just pixels that can send you to a phishing site. Therefore, he advises checking for tampered codes and skipping codes in odd places.
Meanwhile, Alan warns that urgent requests for money are a classic red flag.
Deepfakes and voice clones
About a third of the book covers AI and deepfakes. Frank explains deepfake supremacy, the point where detectors can no longer spot fakes. As a result, he never uses his voice as a password. Criminals often clone a CEO’s voice and call a junior accounts payable worker late on a Friday. In addition, Frank recommends callback numbers and monthly code words to stop these scams.
Online scam protection starts with humility
Frank says the biggest myth is that only other people get scammed. Even Troy Hunt, creator of Have I Been Pwned, was phished while jet lagged. Consequently, Frank urges people to stop blaming victims.
CTRL+ALT+PWN is available on Amazon and wherever books are sold.
Good online scam protection is a habit, not a product. Explore more cybersecurity coverage and the latest Techstrong TV interviews.
For more information please visit frankriccardi.com
Transcript
Hey everyone. Welcome to another Techstrong TV interview. I'm really happy to have my next guest on with me.
His name is Frank Riccardi. Frank's a security person who's recently written a book. We're going to get into that in a second, but let's first welcome him to the show.
Frank, welcome to Techstrong TV. It's great to have you here. Wonderful to be here, Alan.
Thanks for the opportunity. It's an honor and a privilege. Oh my.
Please, don't tell me that too much, it goes to my head. Okay. Hey, Frank.
Speaking though of you, give our audience a little bit of background about your journey, your story. Not the book story right now, but your journey, the Frank Riccardi story. Sure.
So, I'm a retired former chief compliance and privacy officer in the healthcare industry, where I worked with large healthcare systems that had hospitals and physician practices, and other healthcare entities and organizations. And I started out my career, well, I was dragged into cybersecurity kicking and screaming, because- Most of us are. Yeah.
I'm a lawyer by trade, so when I started my career, in healthcare, my expertise was anti-kickback law, particularly physician anti-kickback law, Medicare coding and billing, conflicts of interest, and building out compliance programs. And as I grew my career, and I started getting director and VP jobs, every time I got a chief compliance officer job, they always tacked privacy on. So I was chief compliance and privacy officer, which meant now I was responsible for HIPAA privacy, cybersecurity, managing data breaches and cyber attacks, and that's how I got kicked and dragging from the legal side of it to the world of cybersecurity, and I never looked back.
Guilty. I also went to law school, practiced law. Okay.
Computers weren't my love, and I never looked back either. I started my first tech company in the mid-'90s and- Mm. never looked back.
I've been in tech ever since. I really always felt like I was an entrepreneur, though- Yeah ... starting companies.
But that's interesting. So many attorneys, especially in cyber, believe it or not, there is an affinity there. Mm-hmm.
Right? Yep. That lends itself to it.
And then, look, the security thing in healthcare, you were in a very specific area. Mm-hmm. Right?
And the kickbacks between big pharma- Yeah ... and little pharma, right? The generic manufacturers and stuff like this.
It's been a problem. Back in the day, I knew this as well. Yeah.
What are you doing now? Well, you mentioned you're retired, but I'm sure you're not just home twiddling your thumbs. No.
So I retired in 2021 at the height of the global pandemic. And retirement was very difficult for me. I had been a healthcare executive for 25 years, and I needed something to do, and I decided that I wanted to start writing a book about...
" And I wrote that book because I was always looking for a book when I was chief privacy officer, that I could give my board of directors and my senior leaders, my C-suite, something that they could quickly understand cybersecurity and privacy, because they weren't into it. They were marketers and legal people and HR people and financial people, and the IT part, they didn't care for. And I wanted something that could give that to them in an engaging way.
Since I never found one, I decided to write it myself. Okay. And then later, my next book is "Control Alt Pwn: The Hacker's Playbook and How to Beat It," and I wrote that one because I wanted to write a book not for C-suite leaders, but for everyone.
Excellent. So after a career of cyber, you turned to writing. We spoke offline about my own book coming out.
I'll be very honest with you, I've had similar thoughts myself. Let's get into this new book, though. " Pwn.
Pwn. Right. Pwn rhymes with phone or loan.
Yes. Yeah, rhymes with own. And when you say for everyone, it's not meant necessarily for cyber folks, it's meant- Correct ...
for everyone else. Yeah. It's appropriate for cybersecurity people because they can use it to help their families and friends and neighbors and their colleagues and their coworkers, but I really wrote it for everyday people that don't know a lot about cybersecurity, don't understand hacking, to help them learn how they can protect themselves.
Frank, if you're like me and most of my IT friends out there, we've been doing security consulting and tech support for our friends and relatives- Yeah ... for free. Yeah.
For as long as we can remember, right? Yeah. " Yeah.
But all kidding aside, in the age of AI- Mm-hmm ... it's become worse- Mm-hmm ... than it ever was, and harder than it ever was- Yeah ...
for folks who are not technically inclined- Mm-hmm ... to tell the difference between phishing emails or- Mm-hmm ... phone smishing or- Yeah ...
so many different vectors and paths that the bad guys are using now. Mm-hmm. Let's say this.
Okay. Top three things people should do to try to protect themselves. So, good question.
One of the big themes of the book is that it's not the technology that pwns you, it's the trickery. Yeah. The technology is almost parenthetical to the trickery, and if you understand the trickery, you're less likely to be pwned, you're less likely to be scammed.
And a good example is QR codes. QR codes is an amazing technology that we take for granted because they're slapped everywhere. Right.
But prior to the pandemic, and before they started putting QR code readers on your smartphone, they weren't anywhere. Nobody wanted them. They were actually used in the automotive industry to track parts.
But now they're everywhere, and there's a lot of confusion around them. The FBI, a couple of years ago, put out a fraud alert and said, "Don't scan a QR code because it'll upload ransomware into your phone," even though it's not an executable file, it's not software, it's just pixels. And the trick is, all it can do is direct you to a phishing website if you scan it.
And if you're aware of, okay, could be a phishing website, you understand what a phishing website could look like, you make sure the site you're on is HTTPS, so that it's encrypted. And most importantly, you realize that cyber criminals will take a legitimate QR code and slap a fake one over it, look for signs of tampering, and don't scan QR codes that are in weird, random places like bathroom stalls. So, the technology of the QR code is almost irrelevant.
How they trick you is with these other things, and if you understand the trickery behind it, you're less likely to be scammed. Sort of the modern update of looking for a good time call, and nowadays- Yeah. the QR code in the bathroom stall.
Listening, Frank, to this, I'm reminded when my oldest son, who's now an attorney himself, living up in Boston, when he was in about seventh grade for his school's science project- Mm-hmm ... I reached out to some friends of mine. I think the company was called Hedgehog at the time.
They were out of- Yeah ... Carnegie Mellon University. Mm-hmm.
They had done a phishing educational tool. Mm-hmm. And this is before AI, right?
Phishing was- Right ... not as good as it is now, right? " Ah.
"And go here and put in your old username and password. " Mm-hmm. And we sent that out to his class roster.
Yeah. We got something like 40%, including the teacher- Wow ... including the teacher, clicked on it.
Yeah Put in their username and password to see if it was compromised. Now, of course, we didn't compromise it. It just- Right ...
" But this could have been a bad guy, and- Yeah ... and it was very nice. The Hedgehog company, or whatever they were called, gave the phishing course for free to everyone in the class- Wow ...
and their parents. But it was an eye-opener. Mm-hmm.
And that was back then. Yeah. Right?
Yeah. Phishing's a lot better now. Mm-hmm.
It is bad. So QR codes. " Mm-hmm.
"I need $50," or, "My phone's dead. " Yep. " Or something like this, or, "I'm in the airport," or, "I'm overseas," and what have you.
Advice that I've been giving my friends and relatives- Mm-hmm ... lately is if something is telling you how urgent it is, that you got to do it right now before you have a chance to really think about it- Mm-hmm ... there's a good chance it's not real.
Right? Right. There's an inverse relationship between the urgency that the request is- Mm-hmm ...
how urgent it's making it, versus whether it's legitimate- Yeah ... or not. I'm wondering if that's something you see as well.
It is. Actually, about a third of the book that I wrote deals with artificial intelligence and deepfakes, and there's a chapter on voice cloning and video deepfakes, and I talk about the concept of deepfake supremacy. And what that is, deepfake supremacy is the day when deepfakes are so realistic that software deepfake detectors can no longer detect them.
And an example is if I'm a cybercriminal, and I create a deepfake Alan, the first deepfake I do, you're missing an eyebrow- Right ... you're missing an ear, and you're talking robotically. Well, my deepfake detector picks that up.
" So, with voice cloning, we have achieved deepfake supremacy, and it's one of the reasons I do not use my voice as my password for anything. I want a username and password and MFA. But one of the things I talk about in the book is that voice cloning is the technology.
The trick is what a lot of cybercriminals do is they will clone the voice of a CEO, and then they'll call the accounts payable department. And they're not calling another director or another VP. They want the lowest person that they can find because they want the power differential.
Right. It's a manager versus a CEO. They'll call on Friday at 5:00 before a holiday when your guard is down, and they'll make up some sense of urgency- Urgency ...
that you've got to do something right now. " You can come up with a code word, a monthly code word like tangle bangle jangle, and just ask the person on the other end what's the code word. And if they don't know, then they are a deepfake until proven human.
So there's a lot of internal controls that are not even technological, they're just basic- Right ... that can even defeat or thwart the most realistic deepfake, when a deepfake detector maybe can't because of deepfake supremacy. And then the other thing I add in the book is if your son or daughter is calling, or let's say you're watching somebody on TV and it's an actor that you love, if the person is doing or saying something that they would never do or say in real life, maybe it's a deepfake.
So you just have to be- Frank, I'm sure you're familiar with zero trust, right? Yeah. I think we've got to almost adopt a zero trust attitude these days to our communications.
Mm-hmm. Assume the worst until proven otherwise, right? Mm-hmm.
Yeah. And it's a sad comment on the state of our civilization- Mm-hmm ... but it's probably the prudent thing to do for a lot of people.
Yeah. Especially as you get older, and I'm not saying you and I are old by any means, but as you get older, I just see it with my older relatives and friends- Mm-hmm ... they seem to be more susceptible.
Mm-hmm. Right? And it's not that they're not tech-savvy or less tech-savvy.
And here's the boomerang effect, though. Yeah. A lot of young people, they have no expectation of privacy, they don't think about these things- Mm-hmm ...
and they're equally as susceptible, right? Like the dumbbells, and I don't mean that by saying they're dumb, but like a dumbbell- Yeah ... on both ends of the spectrum.
Well, they're not looking out for themselves. One of the themes of my book is that one of the greatest misconceptions that people have about their online safety and their own ability to be hacked is that the general public thinks that they're not scammable. Right.
They think that other people get scammed, which is why the individual that's a victim of a crypto romance scam loses their 401 . People don't put their finger at the cybercriminal. " And so you have an epidemic of victim-blaming.
Yeah. You know what? You're 100% right, because this could happen to anyone.
Anybody. Yeah. I know plenty of smart people who got scammed.
Well, it happened to Troy Hunt. Yeah. The story of Troy Hunt is in my book.
He's probably the top cybersecurity expert in the world. He created the Have I Been Pwned tool that helps people figure out if they've been a victim of a breach. And he's Australian.
He was in London. He was flying back home to Australia. He had terrible jet lag, and just like everybody else, he goes and checks his emails, probably shouldn't have, and he got phished.
There was a very clever, tricky phish, and cybercriminals stole, I think it was 16,000 email addresses of his followers. Right. So if Troy Hunt can get pwned, I can get pwned, you can get pwned, anybody can.
As long as you've got squishy meatware between your brains and not circuits and not chips, you're not a robot, you can get scammed. And Alan, there's two types of people. There's people that know they can be scammed and people that don't know it, but are going to find out the hard way.
Just haven't been scammed yet. Yeah. But I agree with you.
I actually have met Troy. Oh, okay. Yeah.
Yeah. Awesome. Over the years from a security bloggers network.
But Frank, we're about at, we actually, we're over time. I'm assuming the book's available on Amazon and all the usual places where you buy books. Absolutely.
Amazon and wherever you get your books. Barnes & Nobles, what have you. Yep.
Hey, man, thanks for coming on here. Good job with that. Keep it up, and thank you for doing what you do, Frank.
Well, you're welcome. Thanks for having me on. It was a real treat, and I'm going to be looking for your book October 6th?
" You can check the website. com. I've got some blurbs and all kinds of stuff up there.
But thank you. " Go check it out on Amazon. If you're an IT person, as most of the people watching this are, buy one for all your relatives, and maybe they won't call you quite as much.
We're going to take a break here on TechStrunk TV. We'll be back in a little bit.