Brandon Kovacs from Bishop Fox discusses AI in social engineering. Listener shares overseas trip bank account lock due to VPN. Maryland Lottery warns of phone scam. Catch of the day about a Reddit task scam. Deep dive into deep fakes and software scams.
Deepfake technology advancements enable realistic video and voice clones using consumer-grade tools.
Effective defense strategies against deepfake manipulation include leveraging pre-shared unique information for verification.
Deep dives
The Evolution of Deepfake Technology
Deepfake technology has rapidly advanced to the point where real-time, high-quality deepfakes can be created using consumer-grade hardware. Tools like DeepFace Lab and Retrieval Voice Conversion (RVC) enable the creation of realistic video and voice clones with public data sources. The availability and accessibility of these tools lower the entry barrier for threat actors, signaling potential misuse of this technology for malicious purposes.
Real-time Deepfake Demonstrations
Brandon Kovacs, a senior red team consultant, showcased live deepfake demonstrations during the podcast interview. By leveraging tools like DeepFace Lab and DeepFace Live, he transformed his appearance and voice in real-time, replicating the features of other individuals. The interactive and realistic nature of these demonstrations highlights the substantial progress in deepfake technology.
Security Implications and Lack of Technical Defenses
The podcast underlines the absence of effective technical defenses against deepfake manipulation. Brandon emphasizes the importance of understanding these threats to enhance defense strategies. He suggests leveraging pre-shared information, like unique passwords or secrets, to counter potential deepfake incidents and ensure verification authenticity.
Challenges and Recommendations for Defending Against Deepfake Threats
In response to the growing deepfake threat, recommendations include implementing multi-factor authentication with secret phrases or passwords, enlisting shared knowledge to confirm identities. Developing robust technical defenses to detect deepfakes is crucial, considering the ease of access to deepfake creation tools and their potential misuse for deception and security breaches.
Brandon Kovacs, a Senior Red Team Consultant at Bishop Fox, is talking about how Artificial Intelligence is shaping the future of social engineering. Listener Adina wrote in to share their thoughts on an earlier episode on Google. Dave share's listener Tony's write in for his story this week. Joe and Dave discuss some questions Tony shared about preparing for an overseas trip when his bank account was locked due to security measures triggered by setting up a backup phone and using a VPN. Joe has two stories for this week, one from Blair Young at WBAL, where Maryland Lottery is warning the public about a phone scam claiming Powerball winnings. The second comes from listener Don who shares a story on people who hold posters up saying they need money for children's funerals. Our catch of the day comes from a listener that found a "task scam" on Reddit.
Please take a moment to fill out an audience survey! Let us know how we are doing!