Smashing Security podcast #134: Sextortion, silicone face masks, and a DDoS doofus

Smashing Security #134: Sextortion, silicone face masks, and a DDoS doofus

Scammers steal millions by impersonating a French politician, we offer fashion tips for DDoS attackers, and hear how a small town fought a sextortionist preying on young women.

All this and much more is discussed in the latest edition of the award-winning “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Jessica Barker.

0:00
0:00 0:00
0:00
Show full transcript
TranscriptThis transcript was generated automatically, probably contains mistakes, and has not been manually verified.
GRAHAM CLULEY
Jess Crowe, have you ever firebombed a building?
CAROLE THERIAULT
Oh, firebombed. I just— I only heard cocktail. A Molotov cocktail. Okay, okay, okay, okay, okay.
GRAHAM CLULEY
I was— Yes. You've had cocktails at the Bank of Israel.
CAROLE THERIAULT
So first he tries to DDoS them. That doesn't work. And then he decides to firebomb the bank.
GRAHAM CLULEY
He doesn't throw a baby sham at them.
CAROLE THERIAULT
He throws a Molotov cocktail.
Unknown
Smashing Security, Episode 134: Sextortion, Silicon Face Masks, and a DDoS Doofus with Carole Theriault and Graham Cluley.

Hello, hello, and welcome to Smashing Security, Episode 134. My name is Graham Cluley, and I'm Carole Theriault. Hello, Carole!
CAROLE THERIAULT
Hello!
GRAHAM CLULEY
Hi, and we are joined today by a returning guest. She's come back by popular demand. It's Jessica Barker from Sygenta. Hello, Jessica!
CAROLE THERIAULT
The amazing Jessica Barker from Sygenta, I think you'll find.
JESSICA BARKER
That's— I mean, that's in my contract. You're supposed to say that. Hello, it's wonderful to be back.
CAROLE THERIAULT
Come on, Graham.
GRAHAM CLULEY
It's great to have you back as well. Now, without further ado, plenty to talk about this week, I believe, Carole. What's coming up on this week's show?
CAROLE THERIAULT
Well, first thing is to thank this week's sponsors, LastPass and Edgewise. Their support helps us give you this show for free. On today's show, Mr.

Cluley, you share a wacky story about a DDoS attack in Belgium.

Jessica Barker heads to the next door country, la belle France, not to scoff a delicious croissant, but to showcase a political spearphish with a twist.

And I yak up at all things cyberbullying and sextortion, sharing takeaways for victims, parents, and teachers.

All this and buckets more coming up on this episode of Smashing Security.
GRAHAM CLULEY
Now, chaps, chaps, are you good at complaining?
CAROLE THERIAULT
You are. God, daily. That's the sound I hear out of his mouth most often.
GRAHAM CLULEY
Well, sometimes. Ah, geez. Sometimes we all need to complain about something, don't we? If we're frustrated by poor customer service, for instance.
CAROLE THERIAULT
Or friendships, yeah.
GRAHAM CLULEY
If you've got a problem, it can be hard to get a company's attention. How do you get a company's attention when their customer service sucks? What do you do?
JESSICA BARKER
Twitter.
GRAHAM CLULEY
Twitter is a great way to do it. That's one of my preferred ways to do it. I've never done that.
CAROLE THERIAULT
I've never done that yet.
JESSICA BARKER
I hate doing it. I try to just keep it back for extreme circumstances, but it can be quite effective.
CAROLE THERIAULT
Right.
GRAHAM CLULEY
I find if you can't get hold of the CEO on the phone or send in a snotty email, do you often call the CEO? No. If you try picketing the head office, all those things can fail.

But sending a tweet and @ing them and they kind of go, emergency, emergency, there's an angry Twitter user.

And it's almost like you sort of get past all the automated phone systems and get to someone.
CAROLE THERIAULT
I feel though that those with many Twitter followers, Graham Cluley, might find it easier to complain on Twitter than perhaps normal people?
GRAHAM CLULEY
No, I'm sure if Stephen Fry or somebody like that was to complain about a company, then maybe they do sort of put him higher up on the list. But I don't think it matters that much.

I think normally these days companies have got someone who's monitoring social media, and one of their jobs is if someone's unhappy, you know, sound the alarm, extinguish them as quickly as possible by fixing the problem.
JESSICA BARKER
Yeah, I think they know that any tweet can go viral, however many followers you might have. So I agree, Graham.

I think the best people responding on behalf of companies as well are the ones that can do it with a sense of humor.
GRAHAM CLULEY
Yes, absolutely.
CAROLE THERIAULT
Tesco Mobile, very good at that.
GRAHAM CLULEY
Are they good, are they?
CAROLE THERIAULT
Oh yeah. Hahaha, you got an account with us? No, I'm kidding, I'm kidding.
GRAHAM CLULEY
They laugh at people for having been customers. They'll never be sponsors.
CAROLE THERIAULT
I'm kidding. I'm jesting, for God's sake.
GRAHAM CLULEY
Now, okay, so there's different ways to complain to companies. What I hope you don't do is follow the example of a 35-year-old Belgian known only as Brecht S. Just an empty S.

Now, back in 2014, he was rather upset with a branch of his bank, the Crelan Bank, in a suburb of the city of Roslaere.
CAROLE THERIAULT
In Belgium.
GRAHAM CLULEY
Yes, I make it sound Scottish.
CAROLE THERIAULT
I know, I'm not sure why.
GRAHAM CLULEY
Now, his grumble with the bank account occurred after his parents divorced. He felt that his mother's bank account had somehow sustained a quite substantial loss, €300,000.
CAROLE THERIAULT
People keep that in bank accounts? Just that?
GRAHAM CLULEY
Yes, some people do.
JESSICA BARKER
Do you have yours under the mattress?
CAROLE THERIAULT
Well, I don't have €300,000 lying around, actually.
GRAHAM CLULEY
Anyway, somehow, maybe as a consequence of the divorce, I don't know what, but money had been moved out of an account, and he obviously had a bit of a grumble about this, and his mother was upset too.

And the bank officials simply wouldn't meet with him to discuss the matter. They sort of washed their hands and said, we will not meet you to discuss it.
CAROLE THERIAULT
Are you kidding me? €300,000? They didn't care?
GRAHAM CLULEY
Well, I think as far as they were concerned, it was quite a legitimate transaction.
CAROLE THERIAULT
Oh, I see.
GRAHAM CLULEY
So it wasn't their fault.
CAROLE THERIAULT
Okay.
GRAHAM CLULEY
But clearly somewhere along the line, he was very, very unhappy.
CAROLE THERIAULT
Brecht held them responsible.
GRAHAM CLULEY
Exactly. Now you might think, as we are the Smashing Security podcast, that he would launch a DDoS attack, a denial of service attack against the bank in response to this.
CAROLE THERIAULT
Okay. Yeah, maybe.
GRAHAM CLULEY
Yeah. If you thought that, you'd be right.
CAROLE THERIAULT
Good one, Graham.
GRAHAM CLULEY
Boom, boom. I did a twist there. You weren't expecting that.
JESSICA BARKER
Yeah.
CAROLE THERIAULT
Yeah.
JESSICA BARKER
It was a double twist.
CAROLE THERIAULT
He's clever, he's clever.
GRAHAM CLULEY
So he actually launched this denial of service attack, which basically turned the online portal into porridge.

And he did that for many hours on multiple occasions, according to ZDNet. We can read more about the story. But of course, a DDoS attack uses other people's computers, right?
CAROLE THERIAULT
Yeah, right.
GRAHAM CLULEY
To bombard a website with traffic. So it won't necessarily mean that the authorities are able to easily identify who the actual mastermind of the attack was.
CAROLE THERIAULT
Yeah, yeah, 'cause you have to kind of untangle the whole obfuscation he might've put in place in order to hide himself.
GRAHAM CLULEY
Yeah, he may have rented computers all around the world without the knowledge of their owners, different countries, all swamping a website with traffic. So that's one thing he did.

But the next method which he used to complain about the poor customer service he'd received—
CAROLE THERIAULT
Even better?
GRAHAM CLULEY
Well, somewhat— Certainly easier for the authorities to find out who was responsible because Brecht decided to throw a homemade Molotov cocktail at his local bank branch.
JESSICA BARKER
Escalated things a little bit then.
GRAHAM CLULEY
Now, I don't know if either of you— Jess, Carole, have you ever firebombed a building?
CAROLE THERIAULT
Oh, firebombed? I only heard cocktail. A Molotov cocktail. Okay, okay, okay, okay.
GRAHAM CLULEY
Yes. You've had cocktails at the bank, obviously.
CAROLE THERIAULT
So first he tries to DDoS them. That doesn't work. And then he decides to firebomb the bank.
GRAHAM CLULEY
He doesn't throw a baby sham at them.
CAROLE THERIAULT
He throws a Molotov cocktail.
JESSICA BARKER
Showing your age a little bit there, Graham. Cocktails have moved on a touch.
GRAHAM CLULEY
Not where I live. But anyway, the thing is, if you've ever tried to firebomb a building, one of the first things you— You want to make that clear, do you?
CAROLE THERIAULT
I'm making it really clear. Nope.
GRAHAM CLULEY
Never, never done it. One of the first things you learn is it's a good idea to be a good distance from your target because otherwise your cardigan or your eyebrows might get singed.

So, well, it didn't get burnt. But what happens is when you're throwing a firebomb, right. I can't believe I'm giving advice on the podcast as to how to throw.
CAROLE THERIAULT
Have you ever done this? Just— I just— Okay, so don't— listeners, do not take this as advice.
GRAHAM CLULEY
I've barely even thrown a cricket ball, to be honest. But anyway, you need a good forceful chuck to lug the firebomb a decent distance, because otherwise it's not going to go. What?
CAROLE THERIAULT
You can't say lug. Lugging is pulling. It's pulling from behind. You can't do that.
GRAHAM CLULEY
No.
CAROLE THERIAULT
Like toss?
GRAHAM CLULEY
Oh yeah, okay. So you're going to be tossing at the banking centre. Okay, that could upset them too. But the thing is that you've got to give it some welly, right?

Because— but giving it some welly does increase the chance that something might fall out of your trousers. And that is potentially— Well, no, no, no, around the back of—
CAROLE THERIAULT
He lost his wallet.
GRAHAM CLULEY
The back pocket of your jeans. Something might pop out like a USB stick. And it was this USB thumb drive that the Belgian police found lying on the pavement.

And obviously contained information.
CAROLE THERIAULT
It was a very small— That's probably the problem with it. If he had had a bigger USB, he would have noticed that it had fallen out of his jacket.
GRAHAM CLULEY
He wasn't going to bring a Seagate hard drive with him, Carole. Put that in his cargo pants.
CAROLE THERIAULT
Just saying.
JESSICA BARKER
You know, let's just go back to floppy disks.
GRAHAM CLULEY
Anyway, it contained information which led police to his door.

And what the Belgian cops discovered was not just that he'd been behind the DDoS attack, against the bank, but also had been involved in other shady cybercriminal activity.
CAROLE THERIAULT
So it was all in the same USB, right? Right.
GRAHAM CLULEY
All kinds of evidence there.

So he turned out to be a member of the elite Belgian chapter of the— I imagine they're the smoothest, most delicious hackers in the Anonymous collective.

And he was also a member of the Cyber Crew hacking group that had previously launched an attack against FIFA in the run-up to the 2014 World Cup.

Anyway, Brecht launched DDoS attacks not only against the bank, but also against a local pizza parlor.
CAROLE THERIAULT
It doesn't really compare to the firebombing. No. Just saying.
GRAHAM CLULEY
No, I suppose not.
CAROLE THERIAULT
And then—
GRAHAM CLULEY
What if it was an American hot or a pepperoni one or something with lots of peppers?
CAROLE THERIAULT
Then it could be American hot.
GRAHAM CLULEY
Now, okay, so he tried to extort money from a pizza company as well, and all kinds of things like that. Now, Brecht has now been sentenced to 18 months in prison.

And ordered to pay €3,000 to the bank for the damage which he caused.
CAROLE THERIAULT
Okay, so it wasn't a very effective firebomb. €3,000. What? He broke the little pillar in the front?
GRAHAM CLULEY
Well, and he also caused problems for the website.
CAROLE THERIAULT
No, I'm just saying €3,000 is not very much money.
GRAHAM CLULEY
Well, I don't know how effective his little cocktail was.
CAROLE THERIAULT
Yeah, okay. Basically, he threw a lit cigarette, it sounds like.
JESSICA BARKER
A match.
CAROLE THERIAULT
It's right.
GRAHAM CLULEY
Anyway, he has been hit with an additional prison sentence of 3 years for the arson.
CAROLE THERIAULT
Wrecked, wrecked, wrecked.
GRAHAM CLULEY
I think we've got some lessons to learn here for everybody, right? First of all, don't firebomb banks. In fact, don't firebomb anybody. It's rather antisocial. Don't do it. Check.

Don't launch DDoS attacks against banks either, Carole or Jessica. If you plan to do that, don't do it. Even if you're grumpy, just tweet them instead.
CAROLE THERIAULT
Actually, she can, because I tend to look after ethical hacking, so she could do that.
GRAHAM CLULEY
Okay, but if we're permitted.
CAROLE THERIAULT
Probably with the agreement of the bank.
JESSICA BARKER
With a contract.
CAROLE THERIAULT
Exactly.
GRAHAM CLULEY
But if you do find yourself in the position of firebombing a bank, don't take with you a USB stick which contains identifying information and details of all your other cybercrime exploits.

Or at least, I don't know, wear a tight pair of jeans or something so it doesn't fall out of your—
JESSICA BARKER
Tights!
GRAHAM CLULEY
Tights! You could wear tights.
CAROLE THERIAULT
No pockets in tights.
JESSICA BARKER
Leggings, yoga pants.
CAROLE THERIAULT
Actually, you know what? Pockets in tights would be quite handy for— well, it would have been when I was 25, I'll tell you.
GRAHAM CLULEY
Aren't they just trousers? Aren't you just describing trousers?
CAROLE THERIAULT
Well, no, you go to clubs, you go dancing, you don't want to be holding your handbag or anything like that, right?
GRAHAM CLULEY
Just wear trousers.
CAROLE THERIAULT
Well, okay.
GRAHAM CLULEY
Why not?
CAROLE THERIAULT
Because we have a choice, Graham.
GRAHAM CLULEY
Oh.
CAROLE THERIAULT
Thanks for your advice.
GRAHAM CLULEY
Lucky you. Anyway, so yeah, so there you are, some helpful fashion advice from Smashing Security, as well as some good other advice.
JESSICA BARKER
Very good top tips, I have to say.
GRAHAM CLULEY
Yes, yes, excellent, yes. Now, Jessica, what's your story for us this week?
JESSICA BARKER
Well, it begins in late 2015 and lasts for a couple of years, and we are moving to France.
CAROLE THERIAULT
Ooh la la.
JESSICA BARKER
When in this story, the French Defence Minister, Jean-Yves Le Drian— that's a tempting metaphor.
CAROLE THERIAULT
Beautiful, beautiful, beautiful.
GRAHAM CLULEY
That sounds a bit like Jean-Yves the drainpipe or something like that. Is that how it translates?
CAROLE THERIAULT
No, no.
JESSICA BARKER
I mean, we'd have to ask the French listeners.
CAROLE THERIAULT
Yeah, if you were dyslexic, maybe.
JESSICA BARKER
So Monsieur Le Drian was impersonated as part of a scam.

In which wealthy individuals were contacted under the guise of a request for financial help for journalists apparently being held hostage in the Middle East.
GRAHAM CLULEY
Oh, hang on. So journalists had allegedly, or maybe they had been, they'd been kidnapped in the Middle East. Someone is trying to raise money to get them released.

And so they're going to rich people like Jean-Yves Le Drian, the French Defence Minister.
JESSICA BARKER
Oh no, so sorry. They weren't going to him.

They were posing as him and going to friends of France, wealthy individuals who had an affinity for the French state and asking them if they would pay the ransom money.

It's quite a clever backstory saying we can't pay the ransom because it's not French policy. We are the government, of course.
CAROLE THERIAULT
We must keep our hands clean. But you, monsieur.
JESSICA BARKER
Exactly. Do your bit for the country and for these poor individuals. Vive la France.
GRAHAM CLULEY
Carole, can I say, for someone who's French-Canadian, your French accent is not as good as mine.
CAROLE THERIAULT
Yes, you're absolutely right.
GRAHAM CLULEY
I think I'm much more convincing.
CAROLE THERIAULT
You are, you are. Yes, you're so good at accents. Carry on, Jessica. I'm riveted.
JESSICA BARKER
So this obviously sounds like classic spear phishing, doesn't it?
CAROLE THERIAULT
Totally, totally.
JESSICA BARKER
Well, actually, this story has a dash of Mission: Impossible to it, and then we start to get the full picture.
CAROLE THERIAULT
Okay.
JESSICA BARKER
So, I'm going to talk through it. The scam started with a call pretending to be from one of Monsieur Le Drian's close circle to the wealthy individual being targeted.

And this individual was contacted, and the advisor, apparent advisor for Monsieur Le Drian said, "We want to set up a video call with the French minister who needs to speak to you." Holy moly.
CAROLE THERIAULT
Yeah. Okay.
JESSICA BARKER
So, then the criminals used Skype video calls and a custom-made silicone mask, which looked a bit like Monsieur Le Drian.
CAROLE THERIAULT
No way.
JESSICA BARKER
They had a set which looked like his office, complete with French flag.
CAROLE THERIAULT
Yeah. Don't knock on the desk too hard. It's just made of MDF.
GRAHAM CLULEY
Oh, this is just awesome.
JESSICA BARKER
And then basically they lit this set quite badly. They had someone there with the silicone mask.
CAROLE THERIAULT
Like a B-rated film, he comes out of the shadows.
JESSICA BARKER
A poor, dodgy connection, dodgy Wi-Fi connection, so the video calls didn't last that long, but with the target and said basically, we need your help to pay the ransom to free these people.
GRAHAM CLULEY
Right.
CAROLE THERIAULT
And we promise to give you a tax break if you try. Yes, and we will forever be ingratiated and grateful and indebted to you, Mr. Millionaire.
JESSICA BARKER
Yeah, and you'll have done your thing for France.
GRAHAM CLULEY
You'd be feeling quite patriotic, wouldn't you?
CAROLE THERIAULT
Helping with a mask. I love it.
JESSICA BARKER
Yeah, there with the mask, the mock set.

So a lot of people didn't pay up, but as with all of these scams, when you're targeting wealthy people, it only takes a few to become victim, and suddenly the criminals have made quite a bit of money.

And they actually made an estimated €80 million.
CAROLE THERIAULT
Okay, that's more than my annual salary by a factor of a little bit.
JESSICA BARKER
It's more than I've got under the mattress, let's put it like that.
CAROLE THERIAULT
€70 million.
JESSICA BARKER
Yeah, so like £70 million.
GRAHAM CLULEY
So that would pay for the set and the Skype account.
JESSICA BARKER
Oh, do you think?
CAROLE THERIAULT
If the whole thing was made of solid platinum?
GRAHAM CLULEY
My goodness.
CAROLE THERIAULT
So this all started in 2015 though?
JESSICA BARKER
2015, and it ran for a couple of years. And then they thought they'd caught the guy behind it.

It was thought to be the work of a convicted French-Israeli con artist called Gilbert Chikli.

And he is currently in jail in Paris facing charges of organised fraud and usurping an identity. But earlier this year, with Chikli safely behind bars, the con started again.
CAROLE THERIAULT
Oh!
JESSICA BARKER
So it's now thought that there is a whole gang out there.
CAROLE THERIAULT
Well, at least two.
JESSICA BARKER
Yeah, yes! Someone to run the camera and someone in the house.
CAROLE THERIAULT
Are they stealing personal items?
GRAHAM CLULEY
The same minister?
JESSICA BARKER
Replicating the same minister.
GRAHAM CLULEY
Because they don't want to get a new mask made, right? Exactly.
CAROLE THERIAULT
3D printers are expensive.
JESSICA BARKER
They're thrifty.
CAROLE THERIAULT
And they've only made 80 million.
JESSICA BARKER
Aha, exactly. So they need to recoup a bit more. They've got a few bills to pay, obviously.
CAROLE THERIAULT
It kind of seems that the takeaways of this are, hey, there's a lot of money to be made here, guys. Go make more sets.
JESSICA BARKER
It goes to show, you know, the attackers are always evolving, unfortunately.

And just when we think, you know, we've all been familiar with CEO fraud for a while, impersonation of people, over email, and those being quite convincing and using some of the same tactics that the criminals used in this, you know, trying to prey on people's good nature, trying to make them feel they're donating to a worthy cause, a time pressure.

So, the importance of being aware of how those tactics are used, but also the fact that just when we get used to one method, the attackers are always going to be trying others.

And just because you see something, just because, you know, they seem to be there on video doesn't mean it's true.
CAROLE THERIAULT
The thing is though, with the soon-to-be probably ubiquitous deepfakes, this type of targeted attack where you have a video, you know, for someone that is pretty celebby and is often on camera, that must be quite easy to kind of maybe grab their face.
GRAHAM CLULEY
And fire a dodgy Skype connection.
CAROLE THERIAULT
Yes. With bad lighting and homemade furniture.
JESSICA BARKER
And they've already been warmed up with the call, so.
CAROLE THERIAULT
Yeah, yeah, yeah.
GRAHAM CLULEY
Hey, can I raise a possible conspiracy theory here?
JESSICA BARKER
Oh, always.
GRAHAM CLULEY
What kind of salary does the French Defense Minister Jean-Yves Le Drian actually make?
CAROLE THERIAULT
Can I do a guess before anyone Googles? I'll do a guess. I'll bet on paper it'd probably be €150,000.
GRAHAM CLULEY
I don't know, but yeah, the thing is it's a lot less than €80 million, isn't it? So I wonder whether—
CAROLE THERIAULT
You think he was in on it the whole time? I'm just saying, he went down to the homemade office, turned the lights down.
GRAHAM CLULEY
It's just a possibility.
CAROLE THERIAULT
There's no mask at all.
GRAHAM CLULEY
I think it's something which the police should just not immediately rule out, that maybe he saw criminals pretending to be him and how much money they could make.

Maybe he might have been tempted.
CAROLE THERIAULT
Well, let's just see if he has a château.
JESSICA BARKER
Oui.
CAROLE THERIAULT
The French version of moat around it.
JESSICA BARKER
Maybe underneath that fake mask. You know, who was really there?
CAROLE THERIAULT
Who's wearing the mask? Oh, definitely deliciously good. Get the popcorn.
GRAHAM CLULEY
It's been a crazy show so far, hasn't it?
CAROLE THERIAULT
Yes.
GRAHAM CLULEY
Bonkers. Carole, what have you got for us this week?
CAROLE THERIAULT
I am going to the land of cyberbullying and stalking. I know it's not a place we want to hang out. It's not a fun place, but I think it's an important subject.

And the reason I chose this topic is based on a long-form Wired article penned by Stephanie Clifford. I pulled together some interesting takeaways from that article.

So my story starts in 2012 in a small wooden town in New Hampshire. Live free or die. That's what they have in their license plates there. I think it's a town called Belmont.

Now Belmont has less than 8,000 people. The biggest employer in town is the local supermarket. And they have this teeny tiny police force with a lone detective.
GRAHAM CLULEY
Is he a teeny tiny lone detective as well?
CAROLE THERIAULT
It's a female actually.
GRAHAM CLULEY
I didn't say anything about sex. I'm just talking about their height.
CAROLE THERIAULT
You said he.
JESSICA BARKER
You said—
CAROLE THERIAULT
Oh, now crime in Belmont normally tended towards things like opioids, thefts, burglaries, things you'd see in small towns.

But suddenly our detective, Rachel Moulton, became aware that a cyberstalker was hounding teens for nude pics.

And then when he didn't get his way, he would take over the victim's Facebook accounts. So here's how it went down.

This girl, 16-year-old girl, she's new to the town, new to the school, and she hasn't yet established a gaggle of buddies or joined any teams yet, right?

So when she gets a Facebook request from a guy called Seth Williams, she clicks accept, right? And typical stalking ensues over the next few weeks, right?

He flatters her, asks her lots of questions, acts like he wants to get to know her, likes what he hears, etc., etc.

And when their online relationship seems pretty stable, he asks for some photos of her body. And she hesitates for a while, but he persists. Come on, come on, come on, come on.

So she finally sends him a photo that she thought of as fun.

And this is of her behind in jeans with plastered handprints from, you know, I guess she was painting her room and she put her hands in the paint and put them on her butt.
GRAHAM CLULEY
Okay. Yeah.
CAROLE THERIAULT
And then sends him that thing, right? She's never met this guy.
GRAHAM CLULEY
It's just a picture of her jeans at the moment, right? With some—
CAROLE THERIAULT
Well, yeah, a fun picture of her rear in jeans. Yeah, with some handprints, right? So, but surprise, surprise, this does not appease him. Seth wants more, right?

And after days or weeks or hours of cajoling, she ends up sending a picture in her pants— or sorry, undies for our North American audience— and eventually sends one of her bare butt, right?

This is of course where he doesn't relent again, demands a full nude, and she says, no, that's where I draw the line. And this is where nasty things ensue.

So he replies, no picture, no Facebook. Now he'd hacked her Facebook and her email and changed the passwords, and she begged him to return the accounts. He refused.

He harassed her by text. She'd block his number, he'd use a new number, she'd block that one, and so on. This went on for months and months.
GRAHAM CLULEY
Oh my goodness.
CAROLE THERIAULT
Yeah, you know, he'd be like, take your clothes off, get fucking naked on camera. I'm gonna have fun fucking with you this summer.

So he's sending her all these horrible texts, right?

And while this teen didn't end up sending any identifiably naked picture, using her Facebook account, he messaged all her friends at her new school where she wasn't yet really established.

And of course, friends became jumpy, and their parents did too, right? Prohibiting her friends with hanging out with her.

And she says, at this time, I never felt so alone in my life, which I can totally understand based on the story.

Yeah, but you can also see other parents going, oh God, you know, she must be up to something. You know, when there's smoke, there's fire.

You can imagine that kind of attitude happening, just wanting to keep your kids safe. And you just feel sorry for this one. Back to our detective, 41-year-old Rachel Moulton.

She starts getting reports from numerous local girls naming online bully Seth Williams.

And so she ends up figuring out that all the victims at one point or another attended the local high school. And it seems all of them felt basically socially unstable.

And weirdly, our bully Seth sends nude pics of other victims to victims he is trying to get nude pics from.

So our girl here was being sent pictures from other girls he was harassing and basically sextorting pictures out of.
GRAHAM CLULEY
Wow.
CAROLE THERIAULT
And because it's such a small town, our girl recognized some of the girls. And our detective did too.

And she was able to identify and cold call these other kids because they hadn't said a word to anyone about this. Not their parents, not a teacher, not a trusted adult.
GRAHAM CLULEY
It feels to me like that's a bit of a mistake by the extortionist doing that, because of course it gives them the ability to sort of band together and think, I'm not the only one who's suffering at the hands of this toe rag.
JESSICA BARKER
You wonder, was he showing off? What was he — why was he doing that?
CAROLE THERIAULT
Yeah, he must have been because he had these girls cowering, right?

And the thing was, according to the detective, family life is not always easy for those whose parents actually knew about it, you know.

Detective Walton said girls would come into the station with parents and she sometimes would have to send the parents out of the room because she says, quote, some of the parents were blaming the girls and were really hard on them.
JESSICA BARKER
That's terrible.
CAROLE THERIAULT
Yeah. So fast forward the story here a little bit. Our detective rolls up her sleeves, right, and starts digging hard and getting to the bottom of this.

Moulton learned that Seth had been able to text from 4 or 5 different numbers using a service like TextFree, a VoIP service that allows users to text without subscribing to a cell plan.

Now Detective Moulton sent out subpoenas.
GRAHAM CLULEY
Yep.
CAROLE THERIAULT
And the developer of TextFree sent back information that included the Apple identifier for Seth's phone.

And with that, she could subpoena Apple for the phone's registration and billing information.

So a little aside here, I'm actually kind of impressed that a detective, a single detective on her own in a town of 7,000+ is able to do this.
JESSICA BARKER
Yeah, she sounds amazing as well, right?
CAROLE THERIAULT
It's pretty commendable, I think.
GRAHAM CLULEY
Sounds awesome. Yeah.
CAROLE THERIAULT
So the results that Moulton got back from Apple were a little confusing, but she landed on a name: Ryan Valle. I don't know if I'm saying this right. V-A-L-L-E.

And he was a 19-year-old graduate from the very same high school.
JESSICA BARKER
Nasty.
CAROLE THERIAULT
The girls who had been victimized by this guy were really suffering, right? One began sleeping in the same bed as her mom, and we're talking teens here.

Several feared that this guy Seth would attack them.
GRAHAM CLULEY
Yeah.
CAROLE THERIAULT
One cried herself to sleep. Another routinely called her mom at work sobbing, terrified about being alone at home. And they battled depression, anxiety, nausea, etc.

Now our detective knows who she thinks it is.
GRAHAM CLULEY
Yeah.
CAROLE THERIAULT
But she knows there's a mountain of paperwork and bureaucratic processes and limitations to local laws, right?
GRAHAM CLULEY
She presumably isn't in a position to tell these victims, I think it's this guy. She can't do that, can she?
JESSICA BARKER
Is she?
GRAHAM CLULEY
Well, I would—
CAROLE THERIAULT
So she decides to get the feds involved, right?

Because of course, nationwide, they have a better legal framework for dealing with cyberstalking and these types of crime, much more than the small town she has or even her state.

But she's also aware that when she gets them involved, they're going to need a really strong case, and that could take years.

Detective Moulton decides to tell a few of the troubled girls that Valet, the former classmate, was a suspect.
GRAHAM CLULEY
Oh, really?
CAROLE THERIAULT
In the hope that it might ease their fears. Quote, they had a sense of this being a huge brute of a person, Moulton said.

And when they found out who it was, some of them were like, really? Yeah, no, apparently he was one of these kinds of people that kind of disappeared in the classroom.

They would say, this is the person in your class, and they'd be like, who? Which guy? They didn't remember him, right?

Anyway, investigators eventually identified 23 stalked victims and suspect there are way more. So this all started in 2012, remember?

This is now 2017, 5 years after the first attack was reported.

And they were able at that point to sentence him to 8 years in prison, which was the high end of the federal sentencing guidelines at the time.
GRAHAM CLULEY
Good.
CAROLE THERIAULT
Wow.
JESSICA BARKER
Yeah, I mean, that detective did amazing work.
CAROLE THERIAULT
And this is another weird thing, right? So this happens. The guy goes to the slammer for 8 years for basically terrorizing 23 girls, right? Young girls.

So you'd kind of expect there'd be some kind of whoops and cheers in the town of Belmont, but the kids didn't want to talk about it. The parents don't want to talk about it.

And when Wired contacted teachers, some of them were like, yeah, I don't really know anything about this.

It's like the shame and the embarrassment associated— people just want to bury it. But the problem with that is that new generations aren't learning how to get around that.

Not that they have to go into details of this exact incident, but it should be on the curriculum now that, hey, these things happen. And, you know, you'll read—
GRAHAM CLULEY
And there's a way of fighting back, and someone can be caught and they can be put away for doing this sort of thing.
JESSICA BARKER
Yeah. And you should talk about this. You shouldn't hide it. We shouldn't try and— you shouldn't feel ashamed or feel like you're to blame.
CAROLE THERIAULT
I have to go on my soapbox just for one sec on this one, right? We have been reading a lot of a sharp increase in the last few years in teen depression, anxiety, suicide.

And this is especially amongst girls, right? Apparently, it's up nearly 100% since the early years of 2000, this century. And this is all based on a book I read last year.

I think it was my pick of the week, The Coddling of the American Mind. So social media and device dependency are considered main attributors.

This is how cyberstalkers are able to worm their way into your life. But how do you limit a teenage girl from her social media or her phone?

Must be about as fun as commuting into London during rush hour, which I did yesterday. 5 and a half hours it took on return trip. Thank you very much. Anyway, so takeaways, takeaways.

So these are things I took away from this. Now to see what you guys think, right?

When the bully is giving his victim all this attention at the beginning, right, asking all the questions, things like what's your favorite color or ice cream, or depending on how old you are, right, he's actually curating and collecting information for the account takeover.

And that's a real psychological annoyance for a young girl who may be feeling out of sorts and needs a friend, right?

Because suddenly what you want is someone to listen to you and ask you questions, and really you're answering your security questions that will allow them to take over your Facebook or whatever, Instagram, or whatever account you have.

And also, the stalkers seem to ease them into feeling comfortable, or making the victims think it's okay in stages.

So for example, Graham, if you send pics of your moobs one day to someone and nothing bad happens, you might be more comfortable the next day.

You know, to send a picture of your hairy butt or something.
GRAHAM CLULEY
Hello, what? Can we leave my body out of this?
CAROLE THERIAULT
Well, I'm just saying, you know, it's not a case of in for a penny, in for a pound, but lots of people kind of go, oh, I already did that, it's not so bad.

So you kind of use that kind of mental breakdown of your wall.
JESSICA BARKER
It's like classic grooming, isn't it? Yeah, just a bit at a time, slowly eroding exactly what someone's comfortable or not comfortable with.
CAROLE THERIAULT
And my other big one was, don't assume parents handle this very well, especially if their daughters have been duped into compromising themselves by sending pictures to an idiot that's going to then drag their name through the dirt online.

And thinking about this when I was reading this article, I am not sure my own dad would have handled this very well at all.
GRAHAM CLULEY
No, but let's be honest, if you're a teenager, you don't often want to talk to your parents about anything. Right?

I don't think it's necessarily that they would handle this specifically badly, and I think many parents actually would have the best intentions.

It's simply that you can't communicate anymore, or it's simply too embarrassing to talk with your parents who are just, oh, they're so uncool, about these things because they're too personal.

It's almost like you need a school counselor or someone like that who you can turn to and talk about with these things, because sometimes I think it's just simply too close to discuss it with your parents.
CAROLE THERIAULT
Yeah. Totally. And I think that's a really important thing, you know.

My personal advice in all this is, if you ever get to any crossroad on any decision, right, all you got to ask yourself is, is this good for me?
JESSICA BARKER
Right?
CAROLE THERIAULT
That's the question. The honest answer is no, then, you know, don't follow the Nike motto of just do it. Just trust yourself and absolutely do not do it. Walk away.

That's my big takeaway.
JESSICA BARKER
But I think we need to talk about this stuff so much more because even adults feel ashamed when they're caught up in sextortion.

Or they sometimes feel ashamed when they're caught up in this kind of extortion scam.

And I've done awareness raising for companies where I've said, one thing I'm going to talk about is sextortion. They say, oh, we'd rather you didn't bring that up, actually.

And I'm like, what? Why? Why are we uncomfortable talking about this?

Because if we continue to be uncomfortable, then people are going to keep hiding it, keep feeling ashamed, and then the criminals are winning.
CAROLE THERIAULT
100%.

And if we can't get our act together to talk about these things openly, honestly, and transparently, how do we expect a freaking 16-year-old girl to come forward and say, yeah, let me explain everything that happened to me, all the mistakes I made, and let's tell everybody about them.

And yeah, here's my name. It's just too much. It's too much.
GRAHAM CLULEY
I think it's natural to feel uncomfortable. I feel slightly uncomfortable right now because Carole was talking about my hairy butt.
JESSICA BARKER
We all feel uncomfortable.
CAROLE THERIAULT
I have some links on all things cyberbullying, some great links. There's actually games for kids and all kinds of resources. Check them out at the Smashing Security webpage.

Sorry, I know it wasn't a hilarious one this week, but, you know, important.
JESSICA BARKER
Very important.
CAROLE THERIAULT
Yeah.
GRAHAM CLULEY
Have you finished? Is it safe for me to come out now?
CAROLE THERIAULT
No, keep your trousers on.
GRAHAM CLULEY
So, Carole, imagine a hacker has gained access to one of the computers inside your organization.
CAROLE THERIAULT
Dun dun dun.
GRAHAM CLULEY
And of course, they're going to take advantage of any flat networks and ineffective security controls to try and move laterally towards their intended targets, which is gonna be all that juicy data your company collects.
CAROLE THERIAULT
Gotcha. Yep.
GRAHAM CLULEY
Right. Now, traditional solutions, they often find it difficult to reliably distinguish between legitimate software access and that data and unapproved applications.
CAROLE THERIAULT
Yeah. Okay.
GRAHAM CLULEY
Yeah, yeah, yeah. Right. And that's where our sponsor comes in this week. Edgewise is the industry's first zero-trust segmentation platform.
CAROLE THERIAULT
OK.
GRAHAM CLULEY
It has a simple-to-use interface which lets you stop data breaches by allowing only verified software to communicate within your cloud or data center.
CAROLE THERIAULT
Clever.
GRAHAM CLULEY
Yeah, really smart. In a nutshell, Edgewise's data-centric approach makes micro-segmentation simpler and more secure.
CAROLE THERIAULT
OK, I want to learn more.
GRAHAM CLULEY
Well, that's easy. All you have to do is go to edgewise.net and request a trial of their one-click micro-segmentation.
CAROLE THERIAULT
Awesome. Boom.
CAROLE THERIAULT
Hey Graham, yes, there are people out there with companies a little bit bigger than ours, and one of the issues that they face is visibility and oversight.

And when it comes to cybersecurity, that is super important. So listeners, listen up.

If you do not have a password manager in your organization, please check out LastPass Enterprise.

They offer centralized admin oversight and control, shared access, and automated user management. All this stuff makes your life easier.

Plus, you can even use LastPass's single sign-on to protect all your cloud apps and give seamless access to employees.

Check it out at Smashing Security— no, at— check it out at lastpass.com/smashing. Let me try that again, folks. Check it out at lastpass.com forward slash smashing. Perfect.
GRAHAM CLULEY
Do you want to make it more conversational?
JESSICA BARKER
I don't know.
CAROLE THERIAULT
I think that sounded great.
GRAHAM CLULEY
And welcome back. Can you join us on our favourite part of the show? The part of the show that we like to call Pick of the Week.
CAROLE THERIAULT
Pick of the Week. Pick of the Week.
GRAHAM CLULEY
Pick of the Week is the part of the show where everyone chooses something they like.

Could be a funny story, book that they've read, a TV show, a movie, a record, a podcast, a website, or an app, whatever they wish.

It doesn't have to be security-related necessarily.
CAROLE THERIAULT
Better not be.
GRAHAM CLULEY
And my pick of the week this week is not security-related. It is actually a book.

I always say it could— sorry, I always say it could be a funny story, a book that they've read, a TV show, movie, a record, etc., etc.
CAROLE THERIAULT
You don't read.
GRAHAM CLULEY
But I have actually bought a book.
CAROLE THERIAULT
Oh, okay, you've bought one.
GRAHAM CLULEY
Now let me tell you about this book. Oh yes, exactly, I've bought it for the shelf.
CAROLE THERIAULT
Now, a book, Carole, this is something which comes back.
GRAHAM CLULEY
It's lots of pages. Can you hear those? There you are. Yes.
CAROLE THERIAULT
Oh, it's like a good 20 in there.
GRAHAM CLULEY
So it's hardback, this. This book is called Dreyer's English, or maybe Dreyer's English, I'm not sure. An Utterly Correct Guide to Clarity and Style.

And it is written by the copy chief at Random House called Benjamin Dreyer.

And I'm quite enjoying it because sometimes I'll be in the middle of writing an article, and I'm sort of thinking, oh, is that— am I using that word correctly?

Or is that American? Is it American? Well, it comes in different editions. I chose to buy the English version because obviously—
CAROLE THERIAULT
Oh, very good—
GRAHAM CLULEY
The American edition contains lots and lots of mistakes, like no U's. But the English version is absolutely fine.

I heard about this book in a fun interview which I heard Benjamin Dreyer give with a hero of ours, I think a podcast hero, Preet Bharara.

Preet on the Stay Tuned with Preet podcast of Good Fun Podcast. Go and listen to that. And the interview was my pick of the week. Oh, was it? Oh, there you go. Excellent.

And it's— although it is obviously discussing how to write better, and I have to be very careful what I say now, don't I? Is it write better?
CAROLE THERIAULT
Well, I have a question. Can I— can you check?
GRAHAM CLULEY
Okay, of course, of course.
CAROLE THERIAULT
I've got the book right here. You used to get really pissy with me. We used to have a big fight.
GRAHAM CLULEY
Yeah.
CAROLE THERIAULT
Yes, with the word whilst.
GRAHAM CLULEY
Yes, what's wrong with whilst?
CAROLE THERIAULT
Right, you'd always put it into all your articles, and I was just like, what are you, Middle Ages? Come on, right? And you'd get all like, no, no, no, it's proper English.

So can you just check it up in your Bible?
GRAHAM CLULEY
Okay, I'm gonna look up whilst, and it'd be right at the back of the index here, and it's not in here. So that book's rubbish. So forget that book.
JESSICA BARKER
Are you serious?
GRAHAM CLULEY
It's not even there? It's not there.
JESSICA BARKER
It's such an old-timey word that it doesn't even make it.
GRAHAM CLULEY
No, it's a fine— there's nothing wrong with the word whilst at all.
CAROLE THERIAULT
Okay, Jessica, I think we've made our point. Excellent Pick of the Week. I'm right, you're wrong.
GRAHAM CLULEY
Jessica, what's your Pick of the Week?
JESSICA BARKER
Well, my Pick of the Week is a documentary miniseries that I watched on Netflix. I've actually watched it twice, which I don't often, watch films or TV programs more than once.

I usually get bored the second time, but this documentary miniseries is full of so much stuff that, yeah, I feel I could watch it 100 times. And it is called The Defiant Ones.
CAROLE THERIAULT
Oh, I haven't watched that. I don't know that.
JESSICA BARKER
I highly recommend it, hence it being my pick of the week. It covers the careers of Jimmy Iovine and Dr. Dre.
CAROLE THERIAULT
Okay.
JESSICA BARKER
And in doing so, it explores musical history over the last 4 or so decades, and it has interviews of people like Bruce Springsteen, Snoop Dogg, Eminem, Stevie Nicks, Patti Smith.

Crazy! Everyone who's anyone from rock or hip-hop is interviewed, and, you know, footage of them in the studio concerts. The list goes on. It's amazing.

And it is so outstandingly well directed. Outstandingly well, is that— you'll have to look this up.
GRAHAM CLULEY
I'm gonna have a look. You carry on talking, I'm looking.
JESSICA BARKER
I feel I used those words right.
CAROLE THERIAULT
I think it's fine. You used an adverb and an adjective there. I think it's perfect.
JESSICA BARKER
Oh, thank you. Well, it is supremely directed by Alan Hughes, who apparently I read when I was, you know, looking this up earlier.

Apparently he is working on a TV series documentary about Tupac that's coming next.
CAROLE THERIAULT
Are you a bit of a Tupac fan? I'm a little bit of a hip-hop fan.
JESSICA BARKER
So that is what drew me to The Defiant Ones. And I didn't know much about Jimmy Iovine, I have to be honest, but I found him a really inspiring figure.

And so I was drawn in by the hip-hop angle.
CAROLE THERIAULT
And then it brought you way wider, right?
JESSICA BARKER
Yeah, and I would recommend it to, you know, if you're interested in hip-hop, then it's a given you're gonna this.

If you're interested in rock, then it really covers that and the intersection between rock and hip-hop.

But it's also, it's just a pleasure to watch, partly because of how it's edited.

It's really fun, but it's also so inspiring that if you're interested in innovation or entrepreneurship, you want to think about the world a little bit differently, then this is the kind of thing that just makes you feel you're ready to take on the world.
CAROLE THERIAULT
So put down that Tony Robbins book and check this out instead.
GRAHAM CLULEY
Definitely. Yes. Don't read any Tony Robbins. Exactly. I don't really know anything about hip-hop, but I'd be quite interested in still watching.
CAROLE THERIAULT
Hip-hop?
GRAHAM CLULEY
What's wrong with that?
CAROLE THERIAULT
Is that how you say it?
GRAHAM CLULEY
Hey, I'm actually quite hip, Carole, just so you know. Do they interview Wiki Wiki Wa Wa Wiki Wa Wa Will Smith in this?
JESSICA BARKER
No, not Will Smith. Will.i.am does feature.
CAROLE THERIAULT
I don't think it's in the film. Will.i.am, the stupidest name ever. Is it small i, big a, m or something?
GRAHAM CLULEY
And stupidest spectacle wearer as well. Yeah, he said, I can't really put up with that sort of nonsense.
JESSICA BARKER
Well, don't let that put you off. John Lennon does also feature.
GRAHAM CLULEY
I know you've been told to know his name. Oh, okay.
CAROLE THERIAULT
Now you're talking.
GRAHAM CLULEY
Cool.
JESSICA BARKER
Yeah.
CAROLE THERIAULT
Yeah.
JESSICA BARKER
Give it a whirl.
GRAHAM CLULEY
Good of him to make an appearance.
CAROLE THERIAULT
Yeah. How did they interview him?
JESSICA BARKER
You know, they must have just— They dug him up.
GRAHAM CLULEY
Okay. Oh, please. Right. Right. Okay. So, and it's called The Defiant Ones, and that's on Netflix.
JESSICA BARKER
The Defiant Ones. Yeah. Check it out.
GRAHAM CLULEY
Awesome. Carole, what's your pick of the week?
CAROLE THERIAULT
Okay. You guys have to do something.
GRAHAM CLULEY
Right.
CAROLE THERIAULT
You have to go to a website called mynoise.net.
GRAHAM CLULEY
mynoise.net.
CAROLE THERIAULT
Now, mynoise.net is my pick of the week. It is a collection of noise-scapes. How's that for a modern word?
GRAHAM CLULEY
Okay.
CAROLE THERIAULT
So this is basically that people, more and more of us, are working from home, but it seems as though there's research that suggests that when we have a noisy environment, like a cafe background or office sounds or just something white noisy, it helps us be more productive and we can work longer with more focus.

So this is a site created by an audio processing guru named Stéphane Pigeon.
GRAHAM CLULEY
Stephen the Pigeon.
CAROLE THERIAULT
Exactly, Stephen the Pigeon. Exactly.
JESSICA BARKER
And you— I'm sure that's how you pronounce it.
CAROLE THERIAULT
There is an app as well. There is an app as well. But I've used things like Distant Thunder. That's my favorite. My least favorite is Georgian chants.
GRAHAM CLULEY
Gregorian.
CAROLE THERIAULT
By a long, long— sorry, yes, Gregorian chants. That is definitely not my best.
GRAHAM CLULEY
I've just found one. I've started listening to one. It's called Examination Time.

It says it can be hard to focus in an exam hall full of students when you're used to studying in silence, prepare now so you could have the sound of an examination hall.
CAROLE THERIAULT
Yeah, but there's loads of research that suggests that having mimicking the same environment makes you perform much better because you don't have to then take all the stress of the new environment in.
JESSICA BARKER
Well, here's an interesting one if we're thinking of mimicking an environment. Oblivion. Embrace that darkness.
CAROLE THERIAULT
I think it's an amazing site. So you can get it off Apple Music or Spotify or Deezer, Google Music, Amazon Music, all of them.

And, or you can just check it out probably with your home assistants as well by barking an order at it. mynoise.net. That's my pick of the week.
GRAHAM CLULEY
Cool.
CAROLE THERIAULT
Cool.
GRAHAM CLULEY
Okay. Well, excellent. Well, we chose a book, we chose a documentary, and we chose, well, I don't know what you are, a noise, I suppose, Carole, is what you came up with.
CAROLE THERIAULT
Noisescape.
GRAHAM CLULEY
Noisescapes.
CAROLE THERIAULT
And mine's the coolest.
GRAHAM CLULEY
I wasn't going to say that. And that just about wraps it up for this week. Jessica, I'm sure lots of our listeners would love to follow you online.

What's the best way for folks to do that and find out more about what you're up to?
JESSICA BARKER
Well, check out our website, Cygentr.co.uk, and you can go and have a look at our blogs from there. And then also follow me on Twitter @DrJessicaBarker.
GRAHAM CLULEY
Super duper. And you can also follow us on Twitter @SmashingSecurity, no G, Twitter won't allow us to have a G. And we've got a Reddit community as well.

Just look for Smashing Security up on Reddit.
CAROLE THERIAULT
And thanks once again to this week's Smashing Security sponsors, LastPass and Edgewise. Their support helps us give you this show for free, so be sure to check out their offers.

And fist bumps to all you listeners out there. If you don't know it, you rock.

Check out smashingsecurity.com for past episodes, sponsorship details, and info on how to get in touch with us.
GRAHAM CLULEY
Until next time, cheerio, bye-bye.
JESSICA BARKER
Bye!
CAROLE THERIAULT
Hi. I like that, sounds a bit sexy.
JESSICA BARKER
Ask me where I was yesterday. Where were you?
CAROLE THERIAULT
I was at the NCSC, the National Cybersecurity Center in London.
JESSICA BARKER
Ah, oh, in London.
GRAHAM CLULEY
Oh, the London, not the Cheltenham donut.
CAROLE THERIAULT
Yeah, pretty cool, huh?
JESSICA BARKER
Oh, very good.
CAROLE THERIAULT
How was I can't really say. What were you doing there?
GRAHAM CLULEY
What were you doing there?
CAROLE THERIAULT
I can't really say.
GRAHAM CLULEY
Who were you there to meet?
CAROLE THERIAULT
Graham. I can't say. But I can tell you one thing. They are looking for speakers for their upcoming Cyber Threat 2019 event. And it's in London in November.

Now, I didn't attend last year, but I heard it from very good sources that it's pretty cutting edge and pretty cool.

So if you're a researcher with a cool discovery, or you've suffered a breach and you want to share how much fun that was for you, hahaha. Maybe you should check out the website.

I'll put it in the show notes.
GRAHAM CLULEY
Cool.
CAROLE THERIAULT
Yeah. Boom. Graham, I don't know if it's your bag. Yeah. Bit too advanced. Bit too technical for you, I think.
GRAHAM CLULEY
Bit too technical? You're all right with the groom in your bottom, but it was just a mental image which came up, which wasn't very pleasant.
CAROLE THERIAULT
Can I just apologize now?
GRAHAM CLULEY
You can now, but it's the end of the show now.
CAROLE THERIAULT
I'm sorry, your butt's not her suit.
GRAHAM CLULEY
You're okay.
JESSICA BARKER
What do you want me to say? Done.

Hosts:

Graham Cluley:

Carole Theriault:

Guest:

Jessica Barker – @drjessicabarker

Show notes:

Sponsor: LastPass

LastPass Enterprise makes password security effortless for your organization.

LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.

But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.

Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses.

Sponsor: Edgewise

Edgewise is the industry’s first zero-trust segmentation platform. It’s simple to use interface lets you stops data breaches by allowing only verified software to communicate within your cloud or data centre. Edgewise’s data-centric approach makes micro-segmentation simpler and more secure.

Learn more and get a free trial at edgewise.net.

Follow the show:

Follow the show on Bluesky at @smashingsecurity.com, on the Smashing Security subreddit, or visit our website for more episodes.

Remember: Subscribe on Apple Podcasts, Spotify, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!

Warning: This podcast may contain nuts, adult themes, and rude language.


Graham Cluley is an award-winning keynote speaker who has given presentations around the world about cybersecurity, hackers, and online privacy. A veteran of the computer security industry since the early 1990s, he wrote the first ever version of Dr Solomon's Anti-Virus Toolkit for Windows, makes regular media appearances, and hosts the popular "Smashing Security" podcast. Follow him on TikTok, LinkedIn, Bluesky and Mastodon, or drop him an email.

What do you think? Leave a comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.