Smashing Security podcast #134: Sextortion, silicone face masks, and a DDoS doofus

Smashing Security #134: Sextortion, silicone face masks, and a DDoS doofus

Scammers steal millions by impersonating a French politician, we offer fashion tips for DDoS attackers, and hear how a small town fought a sextortionist preying on young women.

All this and much more is discussed in the latest edition of the award-winning “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Jessica Barker.

0:00
0:00 0:00
0:00
Show full transcript
TranscriptThis transcript was generated automatically, probably contains mistakes, and has not been manually verified.
Graham Cluley

Jess Crowe, have you ever firebombed a building?

Carole Theriault

Oh, firebombed. I just— I only heard cocktail. A Molotov cocktail. Okay, okay, okay, okay, okay.

Graham Cluley

I was— Yes. You've had cocktails at the Bank of Israel.

Carole Theriault

So first he tries to DDoS them. That doesn't work. And then he decides to firebomb the bank.

Graham Cluley

He doesn't throw a baby sham at them.

Carole Theriault

He throws a Molotov cocktail.

Unknown

Smashing Security, Episode 134: Sextortion, Silicon Face Masks, and a DDoS Doofus with Carole Theriault and Graham Cluley. Hello, hello, and welcome to Smashing Security, Episode 134. My name is Graham Cluley, and I'm Carole Theriault. Hello, Carole!

Carole Theriault

Hello!

Graham Cluley

Hi, and we are joined today by a returning guest. She's come back by popular demand. It's Jessica Barker from Sygenta. Hello, Jessica!

Carole Theriault

The amazing Jessica Barker from Sygenta, I think you'll find.

Jessica Barker

That's— I mean, that's in my contract. You're supposed to say that. Hello, it's wonderful to be back.

Carole Theriault

Come on, Graham.

Graham Cluley

It's great to have you back as well. Now, without further ado, plenty to talk about this week, I believe, Carole. What's coming up on this week's show?

Carole Theriault

Well, first thing is to thank this week's sponsors, LastPass and Edgewise. Their support helps us give you this show for free. On today's show, Mr. Cluley, you share a wacky story about a DDoS attack in Belgium. Jessica Barker heads to the next door country, la belle France, not to scoff a delicious croissant, but to showcase a political spearphish with a twist. And I yak up at all things cyberbullying and sextortion, sharing takeaways for victims, parents, and teachers. All this and buckets more coming up on this episode of Smashing Security.

Graham Cluley

Now, chaps, chaps, are you good at complaining?

Carole Theriault

You are. God, daily. That's the sound I hear out of his mouth most often.

Graham Cluley

Well, sometimes. Ah, geez. Sometimes we all need to complain about something, don't we? If we're frustrated by poor customer service, for instance.

Carole Theriault

Or friendships, yeah.

Graham Cluley

If you've got a problem, it can be hard to get a company's attention. How do you get a company's attention when their customer service sucks? What do you do?

Jessica Barker

Twitter.

Graham Cluley

Twitter is a great way to do it. That's one of my preferred ways to do it. I've never done that.

Carole Theriault

I've never done that yet.

Jessica Barker

I hate doing it. I try to just keep it back for extreme circumstances, but it can be quite effective.

Carole Theriault

Right.

Graham Cluley

I find if you can't get hold of the CEO on the phone or send in a snotty email, do you often call the CEO? No. If you try picketing the head office, all those things can fail. But sending a tweet and @ing them and they kind of go, emergency, emergency, there's an angry Twitter user. And it's almost like you sort of get past all the automated phone systems and get to someone.

Carole Theriault

I feel though that those with many Twitter followers, Graham Cluley, might find it easier to complain on Twitter than perhaps normal people?

Graham Cluley

No, I'm sure if Stephen Fry or somebody like that was to complain about a company, then maybe they do sort of put him higher up on the list. But I don't think it matters that much. I think normally these days companies have got someone who's monitoring social media, and one of their jobs is if someone's unhappy, you know, sound the alarm, extinguish them as quickly as possible by fixing the problem.

Jessica Barker

Yeah, I think they know that any tweet can go viral, however many followers you might have. So I agree, Graham. I think the best people responding on behalf of companies as well are the ones that can do it with a sense of humor.

Graham Cluley

Yes, absolutely.

Carole Theriault

Tesco Mobile, very good at that.

Graham Cluley

Are they good, are they?

Carole Theriault

Oh yeah. Hahaha, you got an account with us? No, I'm kidding, I'm kidding.

Graham Cluley

They laugh at people for having been customers. They'll never be sponsors.

Carole Theriault

I'm kidding. I'm jesting, for God's sake.

Graham Cluley

Now, okay, so there's different ways to complain to companies. What I hope you don't do is follow the example of a 35-year-old Belgian known only as Brecht S. Just an empty S. Now, back in 2014, he was rather upset with a branch of his bank, the Crelan Bank, in a suburb of the city of Roslaere.

Carole Theriault

In Belgium.

Graham Cluley

Yes, I make it sound Scottish.

Carole Theriault

I know, I'm not sure why.

Graham Cluley

Now, his grumble with the bank account occurred after his parents divorced. He felt that his mother's bank account had somehow sustained a quite substantial loss, €300,000.

Carole Theriault

People keep that in bank accounts? Just that?

Graham Cluley

Yes, some people do.

Jessica Barker

Do you have yours under the mattress?

Carole Theriault

Well, I don't have €300,000 lying around, actually.

Graham Cluley

Anyway, somehow, maybe as a consequence of the divorce, I don't know what, but money had been moved out of an account, and he obviously had a bit of a grumble about this, and his mother was upset too. And the bank officials simply wouldn't meet with him to discuss the matter. They sort of washed their hands and said, we will not meet you to discuss it.

Carole Theriault

Are you kidding me? €300,000? They didn't care?

Graham Cluley

Well, I think as far as they were concerned, it was quite a legitimate transaction.

Carole Theriault

Oh, I see.

Graham Cluley

So it wasn't their fault.

Carole Theriault

Okay.

Graham Cluley

But clearly somewhere along the line, he was very, very unhappy.

Carole Theriault

Brecht held them responsible.

Graham Cluley

Exactly. Now you might think, as we are the Smashing Security podcast, that he would launch a DDoS attack, a denial of service attack against the bank in response to this.

Carole Theriault

Okay. Yeah, maybe.

Graham Cluley

Yeah. If you thought that, you'd be right.

Carole Theriault

Good one, Graham.

Graham Cluley

Boom, boom. I did a twist there. You weren't expecting that.

Jessica Barker

Yeah.

Carole Theriault

Yeah.

Jessica Barker

It was a double twist.

Carole Theriault

He's clever, he's clever.

Graham Cluley

So he actually launched this denial of service attack, which basically turned the online portal into porridge. And he did that for many hours on multiple occasions, according to ZDNet. We can read more about the story. But of course, a DDoS attack uses other people's computers, right?

Carole Theriault

Yeah, right.

Graham Cluley

To bombard a website with traffic. So it won't necessarily mean that the authorities are able to easily identify who the actual mastermind of the attack was.

Carole Theriault

Yeah, yeah, 'cause you have to kind of untangle the whole obfuscation he might've put in place in order to hide himself.

Graham Cluley

Yeah, he may have rented computers all around the world without the knowledge of their owners, different countries, all swamping a website with traffic. So that's one thing he did. But the next method which he used to complain about the poor customer service he'd received—

Carole Theriault

Even better?

Graham Cluley

Well, somewhat— Certainly easier for the authorities to find out who was responsible because Brecht decided to throw a homemade Molotov cocktail at his local bank branch.

Jessica Barker

Escalated things a little bit then.

Graham Cluley

Now, I don't know if either of you— Jess, Carole, have you ever firebombed a building?

Carole Theriault

Oh, firebombed? I only heard cocktail. A Molotov cocktail. Okay, okay, okay, okay.

Graham Cluley

Yes. You've had cocktails at the bank, obviously.

Carole Theriault

So first he tries to DDoS them. That doesn't work. And then he decides to firebomb the bank.

Graham Cluley

He doesn't throw a baby sham at them.

Carole Theriault

He throws a Molotov cocktail.

Jessica Barker

Showing your age a little bit there, Graham. Cocktails have moved on a touch.

Graham Cluley

Not where I live. But anyway, the thing is, if you've ever tried to firebomb a building, one of the first things you— You want to make that clear, do you?

Carole Theriault

I'm making it really clear. Nope.

Graham Cluley

Never, never done it. One of the first things you learn is it's a good idea to be a good distance from your target because otherwise your cardigan or your eyebrows might get singed. So, well, it didn't get burnt. But what happens is when you're throwing a firebomb, right. I can't believe I'm giving advice on the podcast as to how to throw.

Carole Theriault

Have you ever done this? Just— I just— Okay, so don't— listeners, do not take this as advice.

Graham Cluley

I've barely even thrown a cricket ball, to be honest. But anyway, you need a good forceful chuck to lug the firebomb a decent distance, because otherwise it's not going to go. What?

Carole Theriault

You can't say lug. Lugging is pulling. It's pulling from behind. You can't do that.

Graham Cluley

No.

Carole Theriault

Like toss?

Graham Cluley

Oh yeah, okay. So you're going to be tossing at the banking centre. Okay, that could upset them too. But the thing is that you've got to give it some welly, right? Because— but giving it some welly does increase the chance that something might fall out of your trousers. And that is potentially— Well, no, no, no, around the back of—

Carole Theriault

He lost his wallet.

Graham Cluley

The back pocket of your jeans. Something might pop out like a USB stick. And it was this USB thumb drive that the Belgian police found lying on the pavement. And obviously contained information.

Carole Theriault

It was a very small— That's probably the problem with it. If he had had a bigger USB, he would have noticed that it had fallen out of his jacket.

Graham Cluley

He wasn't going to bring a Seagate hard drive with him, Carole. Put that in his cargo pants.

Carole Theriault

Just saying.

Jessica Barker

You know, let's just go back to floppy disks.

Graham Cluley

Anyway, it contained information which led police to his door. And what the Belgian cops discovered was not just that he'd been behind the DDoS attack, against the bank, but also had been involved in other shady cybercriminal activity.

Carole Theriault

So it was all in the same USB, right? Right.

Graham Cluley

All kinds of evidence there. So he turned out to be a member of the elite Belgian chapter of the— I imagine they're the smoothest, most delicious hackers in the Anonymous collective. And he was also a member of the Cyber Crew hacking group that had previously launched an attack against FIFA in the run-up to the 2014 World Cup. Anyway, Brecht launched DDoS attacks not only against the bank, but also against a local pizza parlor.

Carole Theriault

It doesn't really compare to the firebombing. No. Just saying.

Graham Cluley

No, I suppose not.

Carole Theriault

And then—

Graham Cluley

What if it was an American hot or a pepperoni one or something with lots of peppers?

Carole Theriault

Then it could be American hot.

Graham Cluley

Now, okay, so he tried to extort money from a pizza company as well, and all kinds of things like that. Now, Brecht has now been sentenced to 18 months in prison. And ordered to pay €3,000 to the bank for the damage which he caused.

Carole Theriault

Okay, so it wasn't a very effective firebomb. €3,000. What? He broke the little pillar in the front?

Graham Cluley

Well, and he also caused problems for the website.

Carole Theriault

No, I'm just saying €3,000 is not very much money.

Graham Cluley

Well, I don't know how effective his little cocktail was.

Carole Theriault

Yeah, okay. Basically, he threw a lit cigarette, it sounds like.

Jessica Barker

A match.

Carole Theriault

It's right.

Graham Cluley

Anyway, he has been hit with I think we've got some lessons to learn here for everybody, right? First of all, don't firebomb banks. In fact, don't firebomb anybody. It's rather antisocial. Don't do it. an additional prison sentence of 3 Check. Don't launch DDoS attacks against banks either, Carole or Jessica. If you plan to do that, don't do it. Even if you're grumpy, just tweet them instead. years for the arson.

Carole Theriault

Actually, she can, because I tend to look after ethical hacking, so she could do that.

Graham Cluley

Okay, but if we're permitted.

Carole Theriault

Probably with the agreement of the bank.

Jessica Barker

With a contract.

Carole Theriault

Exactly.

Graham Cluley

But if you do find yourself in the position of firebombing a bank, don't take with you a USB stick which contains identifying information and details of all your other cybercrime exploits. Or at least, I don't know, wear a tight pair of jeans or something so it doesn't fall out of your—

Jessica Barker

Tights!

Graham Cluley

Tights! You could wear tights.

Carole Theriault

No pockets in tights.

Jessica Barker

Leggings, yoga pants.

Carole Theriault

Actually, you know what? Pockets in tights would be quite handy for— well, it would have been when I was 25, I'll tell you.

Graham Cluley

Aren't they just trousers? Aren't you just describing trousers?

Carole Theriault

Well, no, you go to clubs, you go dancing, you don't want to be holding your handbag or anything like that, right?

Graham Cluley

Just wear trousers.

Carole Theriault

Well, okay.

Graham Cluley

Why not?

Carole Theriault

Because we have a choice, Graham.

Graham Cluley

Oh.

Carole Theriault

Thanks for your advice.

Graham Cluley

Lucky you. Anyway, so yeah, so there you are, some helpful fashion advice from Smashing Security, as well as some good other advice.

Jessica Barker

Very good top tips, I have to say.

Graham Cluley

Yes, yes, excellent, yes. Now, Jessica, what's your story for us this week?

Jessica Barker

Well, it begins in late 2015 and lasts for a couple of years, and we are moving to France.

Carole Theriault

Ooh la la.

Jessica Barker

When in this story, the French Defence Minister, Jean-Yves Le Drian— that's a tempting metaphor.

Carole Theriault

Beautiful, beautiful, beautiful.

Graham Cluley

That sounds a bit like Jean-Yves the drainpipe or something like that. Is that how it translates?

Carole Theriault

No, no.

Jessica Barker

I mean, we'd have to ask the French listeners.

Carole Theriault

Yeah, if you were dyslexic, maybe.

Jessica Barker

So Monsieur Le Drian was impersonated as part of a scam.

Carole Theriault

Wrecked, wrecked, wrecked.

Jessica Barker

In which wealthy individuals were contacted under the guise of a request for financial help for journalists apparently being held hostage in the Middle East.

Graham Cluley

Oh, hang on. So journalists had allegedly, or maybe they had been, they'd been kidnapped in the Middle East. Someone is trying to raise money to get them released. And so they're going to rich people like Jean-Yves Le Drian, the French Defence Minister.

Carole Theriault

We must keep our hands clean. But you, monsieur.

Jessica Barker

Exactly. Do your bit for the country and for these poor individuals. Vive la France.

Graham Cluley

Carole, can I say, for someone who's French-Canadian, your French accent is not as good as mine.

Carole Theriault

Yes, you're absolutely right.

Graham Cluley

I think I'm much more convincing.

Carole Theriault

You are, you are. Yes, you're so good at accents. Carry on, Jessica. I'm riveted.

Jessica Barker

So this obviously sounds like classic spear phishing, doesn't it?

Carole Theriault

Totally, totally.

Jessica Barker

Well, actually, this story has a dash of Mission: Impossible to it, and then we start to get the full picture.

Carole Theriault

Okay.

Jessica Barker

So, I'm going to talk through it. The scam started with a call pretending to be from one of Monsieur Le Drian's close circle to the wealthy individual being targeted. And this individual was contacted, and the advisor, apparent advisor for Monsieur Le Drian said, "We want to set up a video call with the French minister who needs to speak to you." Holy moly.

Carole Theriault

Yeah. Okay.

Jessica Barker

So, then the criminals used Skype video calls and a custom-made silicone mask, which looked a bit like Monsieur Le Drian.

Carole Theriault

No way.

Jessica Barker

They had a set which looked like his office, complete with French flag.

Carole Theriault

Yeah. Don't knock on the desk too hard. It's just made of MDF.

Graham Cluley

Oh, this is just awesome.

Jessica Barker

And then basically they lit this set quite badly. They had someone there with the silicone mask.

Carole Theriault

Like a B-rated film, he comes out of the shadows.

Jessica Barker

A poor, dodgy connection, dodgy Wi-Fi connection, so the video calls didn't last that long, but with the target and said basically, we need your help to pay the ransom to free these people.

Graham Cluley

Right.

Carole Theriault

And we promise to give you a tax break if you try. Yes, and we will forever be ingratiated and grateful and indebted to you, Mr. Millionaire.

Jessica Barker

Yeah, and you'll have done your thing for France.

Graham Cluley

You'd be feeling quite patriotic, wouldn't you?

Carole Theriault

Helping with a mask. I love it.

Jessica Barker

Yeah, there with the mask, the mock set. So a lot of people didn't pay up, but as with all of these scams, when you're targeting wealthy people, it only takes a few to become victim, and suddenly the criminals have made quite a bit of money. And they actually made an estimated €80 million.

Carole Theriault

Okay, that's more than my annual salary by a factor of a little bit.

Jessica Barker

It's more than I've got under the mattress, let's put it like that.

Carole Theriault

€70 million.

Jessica Barker

Yeah, so like £70 million.

Graham Cluley

So that would pay for the set and the Skype account.

Jessica Barker

Oh, do you think?

Carole Theriault

If the whole thing was made of solid platinum?

Graham Cluley

My goodness.

Carole Theriault

So this all started in 2015 though?

Jessica Barker

2015, and it ran for a couple of years. And then they thought they'd caught the guy behind it. It was thought to be the work of a convicted French-Israeli con artist called Gilbert Chikli. And he is currently in jail in Paris facing charges of organised fraud and usurping an identity. But earlier this year, with Chikli safely behind bars, the con started again.

Carole Theriault

Oh!

Jessica Barker

So it's now thought that there is a whole gang out there.

Carole Theriault

Well, at least two.

Jessica Barker

Yeah, yes! Someone to run the camera and someone in the house. Oh no, so sorry. They weren't going to him.

Carole Theriault

Are they stealing personal items?

Graham Cluley

The same minister?

Jessica Barker

Replicating the same minister.

Graham Cluley

Because they don't want to get a new mask made, right? Exactly.

Carole Theriault

3D printers are expensive.

Jessica Barker

They're thrifty.

Carole Theriault

And they've only made 80 million.

Jessica Barker

They were posing as him and going to friends of France, wealthy individuals who had an affinity for the French state and asking them if they would pay the ransom money. It's quite a clever backstory saying we can't pay the ransom because it's not French policy. Aha, exactly. So they need to recoup a bit more. They've got a few bills to pay, obviously.

Carole Theriault

It kind of seems that the takeaways of this are, hey, there's a lot of money to be made here, guys. Go make more sets.

Jessica Barker

We are the government, of course. It goes to show, you know, the attackers are always evolving, unfortunately. And just when we think, you know, we've all been familiar with CEO fraud for a while, impersonation of people, over email, and those being quite convincing and using some of the same tactics that the criminals used in this, you know, trying to prey on people's good nature, trying to make them feel they're donating to a worthy cause, a time pressure. So, the importance of being aware of how those tactics are used, but also the fact that just when we get used to one method, the attackers are always going to be trying others. And just because you see something, just because, you know, they seem to be there on video doesn't mean it's true.

Carole Theriault

The thing is though, with the soon-to-be probably ubiquitous deepfakes, this type of targeted attack where you have a video, you know, for someone that is pretty celebby and is often on camera, that must be quite easy to kind of maybe grab their face.

Graham Cluley

And fire a dodgy Skype connection.

Carole Theriault

Yes. With bad lighting and homemade furniture.

Jessica Barker

And they've already been warmed up with the call, so.

Carole Theriault

Yeah, yeah, yeah.

Graham Cluley

Hey, can I raise a possible conspiracy theory here?

Jessica Barker

Oh, always.

Graham Cluley

What kind of salary does the French Defense Minister Jean-Yves Le Drian actually make?

Carole Theriault

Can I do a guess before anyone Googles? I'll do a guess. I'll bet on paper it'd probably be €150,000.

Graham Cluley

I don't know, but yeah, the thing is it's a lot less than €80 million, isn't it? So I wonder whether—

Carole Theriault

You think he was in on it the whole time? I'm just saying, he went down to the homemade office, turned the lights down.

Graham Cluley

It's just a possibility.

Carole Theriault

There's no mask at all.

Graham Cluley

I think it's something which the police should just not immediately rule out, that maybe he saw criminals pretending to be him and how much money they could make. Maybe he might have been tempted.

Carole Theriault

Well, let's just see if he has a château.

Jessica Barker

Oui.

Carole Theriault

The French version of moat around it.

Jessica Barker

Maybe underneath that fake mask. You know, who was really there?

Carole Theriault

Who's wearing the mask? Oh, definitely deliciously good. Get the popcorn.

Graham Cluley

It's been a crazy show so far, hasn't it?

Carole Theriault

Yes.

Graham Cluley

Bonkers. Carole, what have you got for us this week?

Carole Theriault

I am going to the land of cyberbullying and stalking. I know it's not a place we want to hang out. It's not a fun place, but I think it's an important subject. And the reason I chose this topic is based on a long-form Wired article penned by Stephanie Clifford. I pulled together some interesting takeaways from that article. So my story starts in 2012 in a small wooden town in New Hampshire. Live free or die. That's what they have in their license plates there. I think it's a town called Belmont. Now Belmont has less than 8,000 people. The biggest employer in town is the local supermarket. And they have this teeny tiny police force with a lone detective.

Graham Cluley

Is he a teeny tiny lone detective as well?

Carole Theriault

It's a female actually.

Graham Cluley

I didn't say anything about sex. I'm just talking about their height.

Carole Theriault

You said he.

Jessica Barker

You said—

Carole Theriault

Oh, now crime in Belmont normally tended towards things like opioids, thefts, burglaries, things you'd see in small towns. But suddenly our detective, Rachel Moulton, became aware that a cyberstalker was hounding teens for nude pics. And then when he didn't get his way, he would take over the victim's Facebook accounts. So here's how it went down. This girl, 16-year-old girl, she's new to the town, new to the school, and she hasn't yet established a gaggle of buddies or joined any teams yet, right? So when she gets a Facebook request from a guy called Seth Williams, she clicks accept, right? And typical stalking ensues over the next few weeks, right? He flatters her, asks her lots of questions, acts like he wants to get to know her, likes what he hears, etc., etc. And when their online relationship seems pretty stable, he asks for some photos of her body. And she hesitates for a while, but he persists. Come on, come on, come on, come on. So she finally sends him a photo that she thought of as fun. And this is of her behind in jeans with plastered handprints from, you know, I guess she was painting her room and she put her hands in the paint and put them on her butt.

Graham Cluley

Okay. Yeah.

Carole Theriault

And then sends him that thing, right? She's never met this guy.

Graham Cluley

It's just a picture of her jeans at the moment, right? With some—

Carole Theriault

Well, yeah, a fun picture of her rear in jeans. Yeah, with some handprints, right? So, but surprise, surprise, this does not appease him. Seth wants more, right? And after days or weeks or hours of cajoling, she ends up sending a picture in her pants— or sorry, undies for our North American audience— and eventually sends one of her bare butt, right? This is of course where he doesn't relent again, demands a full nude, and she says, no, that's where I draw the line. And this is where nasty things ensue. So he replies, no picture, no Facebook. Now he'd hacked her Facebook and her email and changed the passwords, and she begged him to return the accounts. He refused. He harassed her by text. She'd block his number, he'd use a new number, she'd block that one, and so on. This went on for months and months.

Graham Cluley

Oh my goodness.

Carole Theriault

Yeah, you know, he'd be like, take your clothes off, get fucking naked on camera. I'm gonna have fun fucking with you this summer. So he's sending her all these horrible texts, right? And while this teen didn't end up sending any identifiably naked picture, using her Facebook account, he messaged all her friends at her new school where she wasn't yet really established. And of course, friends became jumpy, and their parents did too, right? Prohibiting her friends with hanging out with her. And she says, at this time, I never felt so alone in my life, which I can totally understand based on the story. Yeah, but you can also see other parents going, oh God, you know, she must be up to something. You know, when there's smoke, there's fire. You can imagine that kind of attitude happening, just wanting to keep your kids safe. And you just feel sorry for this one. Back to our detective, 41-year-old Rachel Moulton. She starts getting reports from numerous local girls naming online bully Seth Williams. And so she ends up figuring out that all the victims at one point or another attended the local high school. And it seems all of them felt basically socially unstable. And weirdly, our bully Seth sends nude pics of other victims to victims he is trying to get nude pics from. So our girl here was being sent pictures from other girls he was harassing and basically sextorting pictures out of.

Graham Cluley

Wow.

Carole Theriault

And because it's such a small town, our girl recognized some of the girls. And our detective did too. And she was able to identify and cold call these other kids because they hadn't said a word to anyone about this. Not their parents, not a teacher, not a trusted adult.

Graham Cluley

It feels to me like that's a bit of a mistake by the extortionist doing that, because of course it gives them the ability to sort of band together and think, I'm not the only one who's suffering at the hands of this toe rag.

Jessica Barker

You wonder, was he showing off? What was he — why was he doing that?

Carole Theriault

Yeah, he must have been because he had these girls cowering, right? And the thing was, according to the detective, family life is not always easy for those whose parents actually knew about it, you know. Detective Walton said girls would come into the station with parents and she sometimes would have to send the parents out of the room because she says, quote, some of the parents were blaming the girls and were really hard on them.

Jessica Barker

That's terrible.

Graham Cluley

Yep.

Carole Theriault

And the developer of TextFree sent back information that included the Apple identifier for Seth's phone. And with that, she could subpoena Apple for the phone's registration and billing information. So a little aside here, I'm actually kind of impressed that a detective, a single detective on her own in a town of 7,000+ is able to do this.

Jessica Barker

Yeah, she sounds amazing as well, right?

Carole Theriault

It's pretty commendable, I think.

Graham Cluley

Sounds awesome. Yeah.

Carole Theriault

So the results that Moulton got back from Apple were a little confusing, but she landed on a name: Ryan Valle. I don't know if I'm saying this right. V-A-L-L-E. And he was a 19-year-old graduate from the very same high school.

Jessica Barker

Nasty.

Carole Theriault

The girls who had been victimized by this guy were really suffering, right? One began sleeping in the same bed as her mom, and we're talking teens here. Several feared that this guy Seth would attack them.

Graham Cluley

Yeah.

Carole Theriault

One cried herself to sleep. Another routinely called her mom at work sobbing, terrified about being alone at home. And they battled depression, anxiety, nausea, etc. Now our detective knows who she thinks it is.

Graham Cluley

Yeah.

Carole Theriault

But she knows there's a mountain of paperwork and bureaucratic processes and limitations to local laws, right?

Graham Cluley

She presumably isn't in a position to tell these victims, I think it's this guy. She can't do that, can she?

Jessica Barker

Is she?

Graham Cluley

Well, I would—

Carole Theriault

So she decides to get the feds involved, right? Because of course, nationwide, they have a better legal framework for dealing with cyberstalking and these types of crime, much more than the small town she has or even her state. But she's also aware that when she gets them involved, they're going to need a really strong case, and that could take years. Detective Moulton decides to tell a few of the troubled girls that Valet, the former classmate, was a suspect.

Graham Cluley

Oh, really?

Carole Theriault

In the hope that it might ease their fears. Quote, they had a sense of this being a huge brute of a person, Moulton said. And when they found out who it was, some of them were like, really? Yeah, no, apparently he was one of these kinds of people that kind of disappeared in the classroom. They would say, this is the person in your class, and they'd be like, who? Which guy? Yeah. So fast forward the story here a little bit. They didn't remember him, right? Anyway, investigators eventually identified 23 stalked victims and suspect there are way more. So this all started in 2012, remember? Our detective rolls up her sleeves, right, and starts digging hard and getting to the bottom of this. Moulton learned that Seth had been able to text from 4 or 5 different numbers using a service like TextFree, a VoIP service that allows users to text without subscribing to a cell plan. This is now 2017, 5 years after the first attack was reported. And they were able at that point to sentence him to 8 years in prison, which was the high end of the federal sentencing guidelines at the time. Now Detective Moulton sent out subpoenas.

Graham Cluley

Good.

Carole Theriault

Wow.

Jessica Barker

Yeah, I mean, that detective did amazing work.

Carole Theriault

And this is another weird thing, right? So this happens. The guy goes to the slammer for 8 years for basically terrorizing 23 girls, right? Young girls. So you'd kind of expect there'd be some kind of whoops and cheers in the town of Belmont, but the kids didn't want to talk about it. The parents don't want to talk about it. And when Wired contacted teachers, some of them were like, yeah, I don't really know anything about this. It's like the shame and the embarrassment associated— people just want to bury it. But the problem with that is that new generations aren't learning how to get around that. Not that they have to go into details of this exact incident, but it should be on the curriculum now that, hey, these things happen. And, you know, you'll read—

Graham Cluley

And there's a way of fighting back, and someone can be caught and they can be put away for doing this sort of thing. Yeah. And you should talk about this.

Carole Theriault

I have to go on my soapbox just for one sec on this one, right? We have been reading a lot of a sharp increase in the last few years in teen depression, anxiety, suicide. And this is especially amongst girls, right? Apparently, it's up nearly 100% since the early years of 2000, this century. And this is all based on a book I read last year. I think it was my pick of the week, The Coddling of the American Mind.

Jessica Barker

Right?

Carole Theriault

So social media and device dependency are considered main attributors. This is how cyberstalkers are able to worm their way into your life. But how do you limit a teenage girl from her social media or her phone? Must be about as fun as commuting into London during rush hour, which I did yesterday. 5 and a half hours it took on return trip. Thank you very much. Anyway, so takeaways, takeaways. So these are things I took away from this. Now to see what you guys think, right? When the bully is giving his victim all this attention at the beginning, right, asking all the questions, things like what's your favorite color or ice cream, or depending on how old you are, right, he's actually curating and collecting information for the account takeover. And that's a real psychological annoyance for a young girl who may be feeling out of sorts and needs a friend, right? Because suddenly what you want is someone to listen to you and ask you questions, and really you're answering your security questions that will allow them to take over your Facebook or whatever, Instagram, or whatever account you have.

Graham Cluley

I think it's natural to feel uncomfortable.

Carole Theriault

And also, the stalkers seem to ease them into feeling comfortable, or making the victims think it's okay in stages. So for example, Graham, if you send pics of your moobs one day to someone and nothing bad happens, you might be more comfortable the next day. You know, to send a picture of your hairy butt or something.

Graham Cluley

I feel slightly uncomfortable right now because Carole Do you want was talking about my hairy butt. to make it more conversational?

Graham Cluley

Hello, what? Can we leave my body out of this?

Carole Theriault

Well, I'm just saying, you know, it's not a case of in for a penny, in for a pound, but lots of people kind of go, oh, I already did that, it's not so bad. So you kind of use that kind of mental breakdown of your wall.

Jessica Barker

It's like classic grooming, isn't it? Yeah, just a bit at a time, slowly eroding exactly what someone's comfortable or not comfortable with.

Carole Theriault

And my other big one was, don't assume parents handle this very well, especially if their daughters have been duped into compromising themselves by sending pictures to an idiot that's going to then drag their name through the dirt online. And thinking about this when I was reading this article, I am not sure my own dad would have handled this very well at all.

Graham Cluley

No, but let's be honest, if you're a teenager, you don't often want to talk to your parents about anything. Right? I don't think it's necessarily that they would handle this specifically badly, and I think many parents actually would have the best intentions. It's simply that you can't communicate anymore, or it's simply too embarrassing to talk with your parents who are just, oh, they're so uncool, about these things because they're too personal. It's almost like you need a school counselor or someone like that who you can turn to and talk about with these things, because sometimes I think it's just simply too close to discuss it with your parents.

Carole Theriault

Yeah. Totally.

Graham Cluley

It's not even there?

Carole Theriault

And I think that's a really important thing, you know. That's the question. The honest answer is no, then, you know, don't follow the Nike motto of just do it. Just trust yourself and absolutely do not do it. Walk away. That's my big takeaway. Oh, I haven't watched that. But I think we need to talk about this stuff so much more because even adults feel ashamed when they're caught up in sextortion. Or they sometimes feel ashamed when they're caught up in this kind of extortion scam. My personal advice in all this is, if you ever get to any crossroad on any decision, right, all you got to ask yourself is, is this good for me?

Graham Cluley

It's not there.

Carole Theriault

100%. And if we can't get our act together to talk about these things openly, honestly, and transparently, how do we expect a freaking 16-year-old girl to come forward and say, yeah, let me explain everything that happened to me, all the mistakes I made, and let's tell everybody about them. I don't know that. And yeah, here's my name. It's just too much.

Jessica Barker

We all feel uncomfortable.

Carole Theriault

I have some links on all things cyberbullying, some great links. There's actually games for kids and all kinds of resources. Check them out at the Smashing Security webpage. Sorry, I know it wasn't a hilarious one this week, but, you know, important. It's too much.

Jessica Barker

Very important.

Carole Theriault

Yeah. I think it's fine.

Graham Cluley

Have you finished? Is it safe for me to come out now?

Carole Theriault

You used an adverb and an No, keep your trousers on.

Graham Cluley

So, Carole, imagine a hacker has gained access to one of the computers inside your organization.

Carole Theriault

adjective there. I think it's perfect. Dun dun dun.

Graham Cluley

And of course, they're going to take advantage of any flat networks and ineffective security controls to try and move laterally towards their intended targets, which is gonna be all that juicy data your company collects.

Carole Theriault

Gotcha. Yep.

Graham Cluley

Right. Now, traditional solutions, they often find it difficult to reliably distinguish between legitimate software access and that data and unapproved applications.

Carole Theriault

Yeah. Okay.

Graham Cluley

Yeah, yeah, yeah. Right. And that's where our sponsor comes in this week. Edgewise is the industry's first zero-trust segmentation platform.

Carole Theriault

OK.

Graham Cluley

It has a simple-to-use interface which lets you stop data breaches by allowing only verified software to communicate within your cloud or data center.

Carole Theriault

Clever.

Graham Cluley

Yeah, really smart. In a nutshell, Edgewise's data-centric approach makes micro-segmentation simpler and more secure.

Carole Theriault

And then it OK, I want to learn more.

Graham Cluley

Well, that's easy. All you have to do is go to edgewise.net and request a trial of their one-click micro-segmentation.

Carole Theriault

Awesome. Boom. brought you way wider, right? Hey Graham, yes, there are people out there with companies a little bit bigger than ours, and one of the issues that they face is visibility and oversight. And when it comes to cybersecurity, that is super important. So listeners, listen up. If you do not have a password manager in your organization, please check out LastPass Enterprise. They offer centralized admin oversight and control, shared access, and automated user management. All this stuff makes your life easier. Plus, you can even use LastPass's single sign-on to protect all your cloud apps and give seamless access to employees. Check it out at Smashing Security— no, at— check it out at lastpass.com/smashing. Let me try that again, folks.

Jessica Barker

I don't know.

Carole Theriault

Check it out at lastpass.com forward slash smashing. Perfect. I think that sounded great.

Graham Cluley

I know you've

Jessica Barker

Yeah.

Carole Theriault

Yeah.

Graham Cluley

And welcome back. Can you join us on our favourite part of the show? been told to The part of the show that we like to call Pick of the Week.

Carole Theriault

Pick of the Week. Pick of the Week.

Graham Cluley

know his name. Oh, okay. Pick of the Week is the part of the show where everyone chooses something they like. Could be a funny story, book that they've read, a TV show, a movie, a record, a podcast, a website, or an app, whatever they wish. It doesn't have to be security-related necessarily.

Carole Theriault

Better not be.

Graham Cluley

Right. And my pick of the week this week is not security-related. It is actually a book. I always say it could— sorry, I always say it could be a funny story, a book that they've read, a TV show, movie, a record, etc., etc.

Carole Theriault

You don't read.

Graham Cluley

But I have actually bought a book.

Carole Theriault

Oh, okay, you've bought one.

Graham Cluley

Now let me tell you about this book.

Carole Theriault

You have to

Graham Cluley

Oh yes, exactly, I've bought it for the shelf.

Carole Theriault

go to a Now, a book, Carole, this is something which comes back.

Graham Cluley

It's lots of pages. Can you hear those? There you are. Yes.

Carole Theriault

website called mynoise.net. Oh, it's like a good 20 in there. So it's hardback, this. This book is called Dreyer's English, or maybe Dreyer's English, I'm not sure. An Utterly Correct Guide to Clarity and Style. And it is written by the copy chief at Random House called Benjamin Dreyer. Oh, very good—

Graham Cluley

The American edition contains lots and lots of mistakes, like no U's. But the English version is absolutely fine. I heard about this book in a fun interview which I heard Benjamin Dreyer give with a hero of ours, I think a podcast hero, Preet Bharara. Preet on the Stay Tuned with Preet podcast of Good Fun Podcast. Go and listen to that. And the interview was my pick of the week. Oh, was it? Oh, there you go. Excellent. And it's— although it is obviously discussing how to write better, and I have to be very careful what I say now, don't I? Is it write better?

Carole Theriault

Well, I have a question. Can I— can you check? I think it's an amazing site. So you can get it off Apple Music or Spotify or Deezer, Google Music, Amazon Music, all of them.

Graham Cluley

Okay, of course, of course.

Carole Theriault

I've got the book right here. You used to get really pissy with me. We used to have a big fight. And, or you can just check it out probably with your home assistants as well by barking an order at it. mynoise.net.

Graham Cluley

Yeah.

Carole Theriault

Yes, with the word whilst. That's my pick of the week.

Graham Cluley

Yes, what's wrong with whilst?

Carole Theriault

Right, you'd always put it into all your articles, and I was just like, what are you, Middle Ages? Come on, right? And you'd get all like, no, no, no, it's proper English. So can you just check it up in your Bible?

Graham Cluley

Okay, I'm gonna look up whilst, and it'd be right at the back of the index here, and it's not in here. So that book's rubbish. So forget that book.

Jessica Barker

Are you serious? It's such an old-timey word that it doesn't even make it.

Graham Cluley

No, it's a fine— there's nothing wrong with the word whilst at all.

Carole Theriault

Okay, Jessica, I think we've made our point. Excellent Pick of the Week. I'm right, you're wrong.

Graham Cluley

Jessica, what's your Pick of the Week?

Jessica Barker

Well, my Pick of the Week is a documentary miniseries that I watched on Netflix. Oh, very good. I've actually watched it twice, which I don't often, watch films or TV programs more than once. I highly recommend it, hence it being my pick of the week. It covers the careers of Jimmy Iovine and Dr. Dre. I usually get bored the second time, but this documentary miniseries is full of so much stuff that, yeah, I feel I could watch it 100 times.

Carole Theriault

Okay.

Jessica Barker

And it is called The Defiant Ones. And in doing so, it explores musical history over the last 4 or so decades, and it has interviews of people like Bruce Springsteen, Snoop Dogg, Eminem, Stevie Nicks, Patti Smith. Crazy! Everyone who's anyone from rock or hip-hop is interviewed, and, you know, footage of them in the studio concerts.

Graham Cluley

I'm gonna have a look. You carry on talking, I'm looking.

Jessica Barker

I feel I used

Carole Theriault

Can I just apologize now?

Jessica Barker

Oh, thank you. Well, it is supremely directed by Alan Hughes, who apparently I read when I was, you know, looking this up earlier. Apparently he is working on a TV series documentary about Tupac that's coming next. those words right.

Carole Theriault

Are you a bit of a Tupac fan? I'm a little bit of a hip-hop fan.

Jessica Barker

So that is what drew me to The Defiant Ones. And I didn't know much about Jimmy Iovine, I have to be honest, but I Yeah, and I would recommend it to, you know, if you're interested in hip-hop, then it's a given you're gonna this. If you're interested in rock, then it really covers that and the intersection between rock and hip-hop. found him a really inspiring figure. And so I was drawn in by the hip-hop angle.

Carole Theriault

So put down that Tony Robbins book and check this out instead.

Graham Cluley

Definitely. Yes. Don't read any Tony Robbins. Exactly. I don't really know anything about hip-hop, but I'd be quite interested in still watching.

Carole Theriault

Hip-hop?

Graham Cluley

What's wrong with that?

Carole Theriault

Is that how you say it?

Graham Cluley

Hey, I'm actually quite hip, Carole, just so you know. Do they interview Wiki Wiki Wa Wa Wiki Wa Wa Will Smith in this?

Jessica Barker

No, not Will Smith. Will.i.am does feature.

Carole Theriault

I don't think it's in the film. Will.i.am, the stupidest name ever. Is it small i, big a, m or something?

Graham Cluley

And stupidest spectacle wearer as well. Yeah, he said, I can't really put up with that sort of nonsense.

Jessica Barker

Well, don't let that put you off. John Lennon does also feature.

Carole Theriault

Now you're talking.

Graham Cluley

Cool.

Jessica Barker

Give it a whirl.

Graham Cluley

Good of him to make an appearance.

Carole Theriault

Yeah. How did they interview him?

Jessica Barker

You know, they must have just— They dug him up.

Graham Cluley

Okay. Oh, please. Right. Right. Okay. So, and it's called The Defiant Ones, and that's on Netflix.

Jessica Barker

The Defiant Ones. Yeah. Check it out.

Graham Cluley

Awesome. Carole, what's your pick of the week?

Carole Theriault

Okay. You guys have to do something.

Graham Cluley

mynoise.net.

Carole Theriault

Now, mynoise.net is my pick of the week. It is a collection of noise-scapes. How's that for a modern word?

Graham Cluley

Okay.

Carole Theriault

So this is basically that people, more and more of us, are working from home, but it seems as though there's research that suggests that when we have a noisy environment, like a cafe background or office sounds or just something white noisy, it helps us be more productive and we can work longer with more focus. So this is a site created by an audio processing guru named Stéphane Pigeon.

Graham Cluley

Stephen the Pigeon.

Carole Theriault

Exactly, Stephen the Pigeon. Exactly.

Jessica Barker

And you— I'm sure that's how you pronounce it.

Carole Theriault

There is an app as well. There is an app as well. But I've used things like Distant Thunder. That's my favorite. My least favorite is Georgian chants.

Graham Cluley

Gregorian.

Carole Theriault

By a long, long— sorry, yes, Gregorian chants. That is definitely not my best.

Graham Cluley

I've just found one. I've started listening to one. It's called Examination Time. It says it can be hard to focus in an exam hall full of students when you're used to studying in silence, prepare now so you could have the sound of an examination hall.

Carole Theriault

Yeah, but there's loads of research that suggests that having mimicking the same environment makes you perform much better because you don't have to then take all the stress of the new environment in.

Jessica Barker

Well, here's an interesting one if we're thinking of mimicking an environment.

Graham Cluley

Cool.

Jessica Barker

Oblivion. Embrace that darkness.

Carole Theriault

Cool.

Graham Cluley

Okay. Well, excellent. Well, we chose a book, we chose a documentary, and we chose, well, I don't know what you are, a noise, I suppose, Carole, is what you came up with.

Carole Theriault

Noisescape.

Graham Cluley

Noisescapes.

Carole Theriault

And mine's the coolest.

Graham Cluley

I wasn't going to say that. And that just about wraps it up for this week. Jessica, I'm sure lots of our listeners would love to follow you online. What's the best way for folks to do that and find out more about what you're up to?

Jessica Barker

Well, check out our website, Cygentr.co.uk, and you can go and have a look at our blogs from there. And then also follow me on Twitter @DrJessicaBarker.

Graham Cluley

Super duper. And you can also follow us on Twitter @SmashingSecurity, no G, Twitter won't allow us to have a G. And we've got a Reddit community as well. Just look for Smashing Security up on Reddit.

Carole Theriault

And thanks once again to this week's Smashing Security sponsors, LastPass and Edgewise. Their support helps us give you this show for free, so be sure to check out their offers. And fist bumps to all you listeners out there. If you don't know it, you rock. Check out smashingsecurity.com for past episodes, sponsorship details, and info on how to get in touch with us.

Graham Cluley

Until next time, cheerio, bye-bye.

Jessica Barker

Bye!

Carole Theriault

Hi. I like that, sounds a bit sexy.

Jessica Barker

Ask me where I was yesterday. Where were you?

Carole Theriault

I was at the NCSC, the National Cybersecurity Center in London.

Jessica Barker

Ah, oh, in London.

Graham Cluley

Oh, the London, not the Cheltenham donut.

Carole Theriault

Yeah, pretty cool, huh? How was I can't really say. What were you doing there?

Graham Cluley

What were you doing there?

Carole Theriault

I can't really say.

Graham Cluley

Who were you there to meet? Graham. I can't say. But I can tell you one thing. They are looking for speakers for their upcoming Cyber Threat 2019 event. Cool.

Carole Theriault

Yeah. Boom. Graham, I don't know if it's your bag. Yeah. Bit too advanced. Bit too technical for you, I think.

Graham Cluley

Bit too technical? You're all right with the groom in your bottom, but it was just a mental You can now, but it's the end of the show now. image which came up, which wasn't very pleasant.

Carole Theriault

I'm sorry, your butt's not her suit.

Graham Cluley

You're okay.

Jessica Barker

What do you want me to say? Done.

Hosts:

Graham Cluley:

Carole Theriault:

Guest:

Jessica Barker – @drjessicabarker

Show notes:

Sponsor: LastPass

LastPass Enterprise makes password security effortless for your organization.

LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.

But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.

Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses.

Sponsor: Edgewise

Edgewise is the industry’s first zero-trust segmentation platform. It’s simple to use interface lets you stops data breaches by allowing only verified software to communicate within your cloud or data centre. Edgewise’s data-centric approach makes micro-segmentation simpler and more secure.

Learn more and get a free trial at edgewise.net.

Follow the show:

Follow the show on Bluesky at @smashingsecurity.com, on the Smashing Security subreddit, or visit our website for more episodes.

Remember: Subscribe on Apple Podcasts, Spotify, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!

Warning: This podcast may contain nuts, adult themes, and rude language.


Graham Cluley is an award-winning keynote speaker who has given presentations around the world about cybersecurity, hackers, and online privacy. A veteran of the computer security industry since the early 1990s, he wrote the first ever version of Dr Solomon's Anti-Virus Toolkit for Windows, makes regular media appearances, and hosts the popular "Smashing Security" podcast. Follow him on TikTok, LinkedIn, Bluesky and Mastodon, or drop him an email.

What do you think? Leave a comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.