Smashing Security podcast #303: Secret Roomba snaps, Christmas cab scams, and the future of AI

Industry veterans, chatting about computer security and online privacy.

Graham Cluley
Graham Cluley
@

 @grahamcluley.com
 / grahamcluley

Smashing Security podcast #303: Secret Roomba snaps, Christmas cab scams, and the future of AI

Beware your Roomba’s roving eye, the Finns warn of AI threats around the corner, and watch out when hailing a cab in Dublin…

All this and much more is discussed in the latest edition of the award-winning “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by The Register’s Iain Thomson.

0:00
0:00
Show full transcript
TranscriptThis transcript was generated automatically, probably contains mistakes, and has not been manually verified.
Graham Cluley

And these photos, which have been shared, include pictures of people sat on the loo.

Carole Theriault

And people are sharing these pictures online. People are like, oh, hey, take a look at me.

Unknown

No, no, no, no, no, no, no, no, no, no, they're not okay. Smashing Security, episode 303 secret Roomba snaps, Christmas cab scams and the future of AI with Carole Theriault and Graham Cluley. Hello, hello, and welcome to Smashing Security episode 303. My name's Graham Cluley.

Carole Theriault

And I'm Carole Theriault.

Graham Cluley

And Carole, for our last episode of the year before Crimbo, look who we've got. We've got The Register's Iain Thomson. Hello, Iain.

Iain Thomson

Hello there. How are you this fine and lovely morning?

Carole Theriault

You mean afternoon? Oh, we're doing a transatlantic.

Graham Cluley

I'm actually a little bit like Rudolph the Red-Nosed Reindeer because I have an enormous pimple right on the end of my nose.

Carole Theriault

That's not like Rudolph because that's not— that's not a charming little cute deer with a—

Graham Cluley

Well, it's red, it glows. I'm scared of going out of the house in case people laugh at me.

Carole Theriault

Do you want a trick? Do you want a trick on air?

Graham Cluley

Oh, go on then, Tonya, tell me, tell me.

Carole Theriault

Just tonight when you go to sleep, just dab on a little bit of baking soda, which you probably won't have, so a little bit of toothpaste on your little—

Iain Thomson

Really?

Carole Theriault

Yeah, and it will dry it out by morning.

Iain Thomson

Oh, interesting.

Graham Cluley

Okay.

Carole Theriault

There you go. That's how we open the show.

Graham Cluley

Lots of tips.

Carole Theriault

Before we kick off, shall we thank this week's sponsor, Bitwarden? Award, and it's their support that helps us give you this show for free. Now, coming up in today's show, Graham, what do you got?

Graham Cluley

A hooga, a hooga, a rumba, a rumba.

Carole Theriault

Iain, what about you?

Iain Thomson

Well, I've got a security warning from the Suomis. The Finnish government has been looking into how AI is going to be used to crack your computers over the next 5 years.

Carole Theriault

Oh God. And thank God I'm here, everyone. I have a Christmasy tale of Irish woe. All this and much more coming up on this episode of Smashing Security.

Graham Cluley

Now, chums, chums, listen carefully. You might be able to hear the sleigh bells ringing in the distance. Snow is falling even in San Francisco. It's been a wee bit frosty. Santa is going ho ho ho ho ho ho ho. We're all relaxing and it's time for the Smashing Security Christmas party, of course. Oh, wonderful. Just imagine. I mean, there will be lots of people listening right now who've been to a Christmas party or looking forward to their Christmas party. Imagine the scene. Imagine your boss has invited you to the Christmas party, and he reckons he's a great cook. He claims he can make all the big dishes, all the popular ones, everything people expect at Christmas. Cheesecake filled with strawberries, ham and Coke.

Iain Thomson

Ham and Coke?

Graham Cluley

Yeah, yeah, I've seen people do that before.

Iain Thomson

Oh, good grief.

Graham Cluley

Sea urchin guacamole tacos, macaroni cheese, all of the delicacies, everything. So you're there, right? Maybe you've been invited to Christmas parties like this. We're around at the—

Carole Theriault

You know this is Smashing Security, right? Not Sticky Pickles.

Graham Cluley

I know it's not Sticky Pickles. I know, I know.

Iain Thomson

I was thinking we were going for the Bake Off market, but go on.

Graham Cluley

Yeah. Imagine you're there with all the rest of the crew and your boss is serving up some old slop and it's disgusting. It tastes like donkey vomit that's barely warmed up to room temperature.

Iain Thomson

It's vile.

Graham Cluley

It tastes of rotten fish. But you have to eat it anyway, don't you? Have you been in that situation? We've been round at someone's party and they've served up, oh, it's just disgusting. It's absolutely horrible. And you've got to eat it because you love your job. And you think, oh, well, the only way I'm going to get through this is by drinking. I've got to be drinking, right?

Iain Thomson

Well, you're talking to a journalist here, so that's default position.

Graham Cluley

Yeah, you have to be pushed into eating really, don't you? It's a liquid diet largely. And there you are after the party. You're driving home in the wee small hours of the morning through the city.

Carole Theriault

Piss drunk? Where are you living? You didn't figure that one out? And you crash and die. The end.

Graham Cluley

No, that's not the end of the story. But you feel you can— oh, crumbs. Just your stomach. Oh, blimey.

Iain Thomson

You're feeling a bit—

Carole Theriault

Oh no.

Graham Cluley

You're feeling a bit dicky. Right? You've got a bit of a fever. Your stomach's gurgling. Whatever your boss has fed you, it just isn't agreeing with you.

Carole Theriault

Plus you've got this big zit on your nose, you know.

Graham Cluley

Which is lighting up the road as you drive home.

Carole Theriault

Drunk.

Graham Cluley

You lurch into your bachelor pad. Carole, you're in a spinster's cave or a chick shack or whatever. What is the feminine version of a bachelor pad? About a toilet pad? A home. A home, okay. You live alone. You don't have a partner. It's just you, right? You race to the loo. You pull down your kecks and you let loose.

Carole Theriault

This is just too visual, honey.

Graham Cluley

This is what we're doing. We're painting a picture with words.

Carole Theriault

No one wants to see this picture.

Iain Thomson

Quite literally painting from the sounds of it.

Graham Cluley

Yes. We're decorating the porcelain.

Iain Thomson

We're pebbledashing it. Yes.

Carole Theriault

Thank God I don't have to edit this.

Graham Cluley

And then, and then you hear a noise, right?

Carole Theriault

Click.

Graham Cluley

Something or someone is in the hallway. It's the dead of the night. You're thinking, who could that be? Did you leave the front door open? Could there be a burglar?

Carole Theriault

A robotic burglar?

Graham Cluley

Ah.

Carole Theriault

What about an electric toothbrush?

Graham Cluley

It's not your electric toothbrush. No, no.

Carole Theriault

Coming to attack you, Chucky style.

Iain Thomson

The cat's become a cyborg.

Carole Theriault

Exactly.

Graham Cluley

You try and stay as quiet as you can, right? You're gripped with fear.

Carole Theriault

It's the tuna fish you should have thrown out weeks ago.

Graham Cluley

It's difficult to stay quiet in your current state. You try to clench your buttocks, but— And then it comes around the corner. Oh, thank goodness for that. It's the iRobot Roomba J7 series robot vacuum.

Carole Theriault

Which miraculously appears in your house without you purchasing it?

Graham Cluley

No, you did. You do own one of these.

Carole Theriault

You just forgot.

Iain Thomson

Yeah.

Graham Cluley

It becomes sentient at 2 o'clock in the morning, because that's when people set them to go round the house.

Iain Thomson

No.

Carole Theriault

Who does that?

Graham Cluley

Lots of people do, because you're asleep upstairs. And so you say, do a quick, you know, trawl round the house.

Iain Thomson

At 2 in the morning?

Graham Cluley

Yeah.

Carole Theriault

Not if you live in a bedsit. You put us in a— what was that? A chick shack you offered me.

Graham Cluley

It's a bedsit. It's a bachelor pad.

Carole Theriault

You mean a mansion. You mean a mansion.

Graham Cluley

It might be a duplex. You might normally live upstairs. Anyway, it's your pride and joy. It's your little friend. It's vacuuming your house tirelessly in the middle of the night when normally you'd be asleep. And you think, well, that's all right, isn't it? Doesn't matter. That's safe, isn't it? No, wrong, wrong. Not safe at all. Because as MIT Technology Review has reported, pictures are being taken inside people's homes by Roomba robot vacuum cleaners and are then being shared on social media.

Carole Theriault

Okay.

Graham Cluley

Whoa, whoa, whoa, whoa, whoa, whoa.

Iain Thomson

Yeah.

Carole Theriault

What kind of— okay. Are they pictures of the floor?

Iain Thomson

Pictures on the loo?

Carole Theriault

Yeah. Are they pictures of the floor in front of them? So if I was on the loo, they would see my big toe?

Graham Cluley

I am talking about pictures where the camera is angled upwards. And these photos, which have been shared, include pictures of people sat on the loo.

Iain Thomson

That's. No one wants to see that with me involved.

Carole Theriault

And people are sharing these pictures online. People are like, oh, hey, take a look at me.

Graham Cluley

No, no, no, no, no, no, no, no, no, no, they're not. It's not the owners. No. Because as Technology Review describes, pictures of, for instance, a young woman in a lavender T-shirt sitting on pulled down to mid-thigh are being posted on social media, not by young woman in question.

Iain Thomson

But by?

Graham Cluley

Well, this is the question, isn't it? So there's two big questions as I see it. Number one, who on earth wears a lavender T-shirt? Okay, three big questions.

Carole Theriault

Loads of people wear lavender T-shirts.

Graham Cluley

No, they don't. No, they don't.

Iain Thomson

Yes, they do.

Graham Cluley

No, they don't. I don't know. I don't know. Let's do a test right now. Let's do a survey.

Iain Thomson

I'm just raising my hand here at the moment. I do have a lavender T-shirt.

Graham Cluley

You have a lavender T-shirt?

Carole Theriault

Yes, but it—

Iain Thomson

Admittedly, it does have a picture of Cerebus the Aardvark printed on the front of it, but it is lavender.

Carole Theriault

My hair is currently lavender.

Graham Cluley

Well, I'm outnumbered. Okay, so 3 big questions. Who wears a lavender T-shirt? I think we've answered that one. Next question: why are robot vacuum cleaners taking photographs of people on the loo? And finally, why are these photographs being posted on social media sites? And I hope to explain why this is happening. To you. So, first thing is, these are not regular Roomba vacuum cleaners. These are pimped-up Roomba vacuum cleaners. If you are lucky enough to work for iRobot, the company that makes Roombas, they were recently acquired by Amazon.

Iain Thomson

Yes, everything will be at some point. Yes.

Carole Theriault

Yeah.

Graham Cluley

You might be lucky enough to be gifted a development version of their robot vacuum cleaner, which includes additional software and hardware designed to learn more about life in the outside world.

Carole Theriault

So instead of pimp up my car, pimp up my Roomba.

Graham Cluley

Let's not use the word pimp too much at the moment. It would stick to my nose, if you mind. That'd be good. But yes. So maybe it's Mrs. Geoff Bezos sat on the loo. I don't know.

Iain Thomson

Well, they're not living in the same—

Carole Theriault

Yeah, they're not living in the same house anymore, yeah.

Iain Thomson

Exactly. I'm pretty sure she has a mansion somewhere else.

Carole Theriault

You've not done a lot of research in this story. There is a lot of money.

Graham Cluley

He's got a girlfriend. Hasn't he married his new girlfriend?

Iain Thomson

No, no, they're still just dating and trying. He's just wandering around.

Carole Theriault

Discussing the prenup.

Iain Thomson

Going through his midlife crisis. Oh God, discussing the prenup. That's going to be a long one.

Graham Cluley

So there are people who work for the company who get these vacuum cleaners, these special versions of the vacuum cleaner. But there are also apparently people who are actually paid by Roomba to collect data.

Iain Thomson

Oh, get paid guinea pigs.

Carole Theriault

Like beta testers kind of thing.

Graham Cluley

Yes. I think what's happening is that they basically say, look, if you pay me a little bit of money, I will run your special Roomba around my house and allow you to collect data about me and about my house.

Carole Theriault

Oh, so the fine print. It always comes down to the fine print.

Graham Cluley

So maybe this is their way of getting the robot vacuum on the cheap. And all they have to do is pay with their privacy.

Iain Thomson

Yeah, I mean, I'm sure we both remember InfoSec. There was one PR company that did a questionnaire on would you give over your password for a chocolate bar? And it was typically about 80%. So yeah, Roomba, no surprise there.

Graham Cluley

Yeah, and anyone will say anything for a chocolate bar, won't they? It's the most pointless press release ever, wasn't it?

Iain Thomson

Well, yeah. I mean, 1, 2, 3, 4. Now give me the chocolate bar.

Graham Cluley

Yeah, give me the Cadbury's. So these people apparently sign written agreements acknowledging that they know they are sending data streams, including video, back to the company for training purposes. Now, when I heard about these streams, I was thinking again of the woman on the loo, but it's not data streams. Data streams, please, please, Iain, raise the tone. According to iRobot, these Roombas are labeled with a bright green sticker that reads video recording in progress.

Iain Thomson

And it doesn't have a little thing saying lawsuit averted.

Graham Cluley

And they also say, so Roomba also said, look, you have to remove anything that you deem sensitive from any place the robot operates in, including children. So you have to remove children.

Carole Theriault

Oh my God. You're like, the Roomba's in there. Get out now.

Graham Cluley

Throw the kids in the garden. Little Charlie! Lock them in the airing cupboard. Tell them to hide upstairs. Pretend there's a Dalek in the kitchen. Go upstairs, stay up there until we've dealt with it.

Carole Theriault

Graham, are you suggesting that the reason they say hide your private stuff is because they automatically put it on social? Is that what they're doing?

Graham Cluley

Well, I don't think it is automatic. I don't think it's designed to promote— remember, we're going to get on to—

Carole Theriault

Okay, I'm sorry, I'm just—

Graham Cluley

in a moment. No, but it's an interesting theory.

Iain Thomson

I mean, I have to say, I was just thinking, it's just like, well, hang on, security on IoT devices is pathetically bad, usually. So maybe, is someone hijacking the signal?

Graham Cluley

Right. We've seen this recently, haven't we? We have Eufy webcam doorbell things.

Carole Theriault

Yep.

Graham Cluley

Where they've been uploading, and you can get a livestream from people's doorbells, even though they claimed they weren't sharing anything with the internet.

Iain Thomson

Indeed, also transmitting passwords in plain text over Bluetooth.

Graham Cluley

Right.

Iain Thomson

Very, very popular.

Graham Cluley

So iRobot, when this Technology Review report came out, they're not very happy about it. And they say, look, as far as we're concerned, anyone who appears in these photos or videos, they're perfectly fine with being recorded. Whatever they're doing, they're comfortable with it. And our employee who you caught on the loo or our Roomba caught on the loo, I'm sure they're fine with that because they signed off on it, you know, and they wouldn't have allowed the vacuum cleaner in if they— but the problem is, of course, these things are collecting our personal information. There's so much IoT which is doing this and other services as well.

Carole Theriault

I'm just wondering why you didn't start this story with a couple trying to do a bit of Netflix and chilling, you know, as opposed to the extremely colorful—

Graham Cluley

Because that's the example that was actually shared by MIT Technology Review, was of this woman on the loo.

Iain Thomson

I'm looking at it now and the picture is, yeah. She's sitting there showing—

Graham Cluley

Yeah, she is.

Iain Thomson

Yeah.

Graham Cluley

So why are Roombas collecting this information? To get smarter. That's why they're doing it. They're learning more about the outside world. And the reason why they're not just looking ahead but are angled upwards is because they want to learn more about their environment. And so they're thinking, well, you know, we need to know what's around. And for instance, you might be able to map a room more easily, the dimensions of a room, if you look upwards towards the corner of the ceiling rather than trying to work it out from what you can see at floor level. It kind of makes sense.

Carole Theriault

Is she doing her business in the dark or does it have just a really shit camera?

Iain Thomson

It looks like there's a light on outside, but not in the room itself. God, I feel like a pervert just looking at this.

Carole Theriault

Yeah.

Graham Cluley

I haven't analysed the photo this closely, I must admit. So I can't help with this.

Iain Thomson

Hey, don't blame me. You brought this one up.

Carole Theriault

Hey, you definitely used your imagination, yeah.

Graham Cluley

So, what happens to these pictures and video streams? Well, of course they're uploaded to the internet, right? I mean, you know, surprise, surprise. Where a massively sophisticated AI, artificial intelligence system, analyses every image securely, then securely destru— Oh no, it doesn't do anything like that.

Iain Thomson

I was gonna say, has Graham lost his mind?

Carole Theriault

Yes, a while ago.

Graham Cluley

What happens is— low-paid gig workers. They've got the job of labelling items in each picture and they say, that's a dog poop, that's a chair, that's a stool, that's a frying pan. It sounds like a monotonous job.

Carole Theriault

Oh, to educate the AI.

Graham Cluley

Right.

Iain Thomson

Yeah.

Carole Theriault

With words and images. So try and do that cross. Yep. Yep.

Graham Cluley

And iRobot's founder, his name is Colin Angle. He says that this enables them to build intelligence into their products, object recognition and avoidance, blah, blah, blah, customised cleaning suggestions. That's his angle on all of this.

Iain Thomson

And it's all down to some sod who's got to sit there and click on, this is an image of this, this is an image of that.

Graham Cluley

Right. And I cannot wait for a fucking smart vacuum cleaner. I mean, I just can't wait. You've got your husband, haven't you?

Carole Theriault

I do, actually. He does do all the vacuuming.

Graham Cluley

There you go. There you are. It's the ideal. But of course, these people have now got pictures of your face. And we know that there are services, online services like PimEyes, where you can put in a picture of someone's face and it will tell you who they are and find all their social media accounts and other photographs of them.

Iain Thomson

Clearview AI would love this data.

Graham Cluley

Yeah, well, that's another company.

Carole Theriault

Absolutely. Yeah.

Graham Cluley

So the second question, was it the third question? Why do these images get uploaded to social media? Well, it turns out some of these guys who are the gig workers, the low-paid guys who are trying to label the items, some of them can't tell the difference between a poop and a stool. They can't tell the difference between different items. And so, because it's sometimes unclear, they upload it. You know, on Who Wants to Be a Millionaire, you can use a lifeline or phone a friend or ask the audience. These guys are posting these images onto an online forum with their coworkers saying, what do you think of this then?

Carole Theriault

Oh yeah, but there's obviously a hee hee hee, here's a funny one, guys. Which is why they loaded up the toilet ones.

Iain Thomson

This was on a private forum or on a public one?

Graham Cluley

It sounds like it was a closed group and the images were then later shared with the journalist.

Iain Thomson

As happens, yeah.

Graham Cluley

So that they knew what was going on, as of course, because nothing's really private. But it was being uploaded to social media, closed groups, and of course the social media companies, who knows what they're up to and might be doing with these images as well. So Roomba has, well, first of all, it was a bit annoyed with MIT Technology Review. It said, we asked you not to publish those sensitive images.

Carole Theriault

Yeah, okay, thanks.

Iain Thomson

Yeah, yeah, right, okay. Let's write a story and say.

Carole Theriault

Has that ever worked, Iain? Has that ever worked? I'm sure I begged you once or twice not to write something.

Iain Thomson

I know, well, in fact, I did. There was a long and hard debate, which actually relates to the toilet issue. Do you remember Norse Security? Oh yes, who went spectacularly bust. We broke the story of the bust, but when I— the person who leaked it to, or one of the people who I was speaking to, obviously you've got to ask, can you prove that you're a member of Norse Security? And I said— he said, well, yeah, here's this and here's this. Oh, and here's a picture of the Christmas card they sent us last year. And he sent the company Christmas card with the CEO and his family. And he'd laid one out over it to be polite and sent us the picture.

Graham Cluley

What?

Iain Thomson

He'd literally taken a dump on his boss's photo.

Carole Theriault

And sent it to you? 'Cause you want to see that?

Iain Thomson

No, sent it to me for confirmation he wasn't a pissed-off ex-Norse employee. And there was a huge debate about whether or not to run it. I mean, seriously, it was just well, we could pixelate out their faces. But then we also would have to pixel out the device. And then we've just basically got a thing of pixels. It's not a good picture. We can't do it. Use it, but still got a copy somewhere. Anyway, back to the point.

Graham Cluley

So Technology Review, they actually pixelated out people's faces, the woman on the loo. Yeah. And they sort of said, well, it's more than Roomba did. So iRobot, they say that they are terminating their relationship with the service provider who leaked the images and are investigating and taking measures to stop it from happening again in future, though quite how they're going to do that, I don't know.

Carole Theriault

Sorry, sorry. Where was the sorry there?

Graham Cluley

Yeah, it is.

Carole Theriault

Just a little word. It's not hard, guys. Not hard.

Graham Cluley

Iain, what have you got for us this week?

Iain Thomson

Well, usually government reports are really, really boring. And, you know, it's— they are second only to financial statements when it comes to we've got to cover this story. I'm going to be spending the next 2 hours reading, you know, bland stuff. But amazingly enough, Finland, a nation which punches above its weight in software, hardware for Nokia, drivers for Formula 1 and rallying, and in getting spastically drunk and jumping over fires, which is actually a leading cause of death during the summer solstice.

Carole Theriault

You're kidding.

Iain Thomson

No, they lose a couple of people every year because you go out to the country, you build a big bonfire, you get drunk, and then you jump over it and people trip and fall.

Carole Theriault

What could go wrong?

Iain Thomson

Basically, they've laid out a 5-year plan of where we're going in terms of AI systems being used to hack your computers. Now, this is obviously speculative, but it is taken from, you know, an analysis of what data is out there and what code is there. But it's also— we're going back to probably the early 1990s in terms of security and script kiddies. Because these people, once they get AI enabled, are— you can farm this stuff out to anyone who'll pay. So, I mean, the main problem is they're going to use AI for finding holes in your system. Automatic vulnerability scanning is going to get improved, and then you've got generating data to do proper spear phishing. And finally, it's the speed of reaction. You know, you can't beat a computer when it comes to speed and automation. And this is a point where I disagree with the report. They say there is no evidence of AI attacks. And well, first off, you know, GAN generation of faces could be considered an AI attack. So we're at that stage already. But the main thing at the moment is for phishing. Well, what they're predicting will happen is that you'll go for a vulnerability, you'll find a vulnerability, get in there, and the AI system will automatically look for key data and key individuals who can be targeted in future. So basically, yeah, next couple of years phishing is going to be the major issue. But the big question is, can you get full end-to-end? Malware gets into your system, defeats your security software, reacts to its attempts to cut you out. They're putting that at 5 years. And they're saying it's only gonna come from nation states. So yeah, it's going to come, but I think we're all pretty much divided on when it's going to come.

Carole Theriault

I wonder if, I wonder if this might mean the end of something like apps, right? Because apps won't be able to survive in a world like that. 'Cause they'll all be full of vulnerabilities, right? Like, they come so— now.

Iain Thomson

Yeah. Yeah.

Carole Theriault

Yeah.

Iain Thomson

I think you're right.

Carole Theriault

Yeah. I wonder if we'll, and I'm just wondering if we'd go back to a kind of Google or internet-based method of working.

Graham Cluley

Oh, because those can't have vulnerabilities, you mean?

Carole Theriault

No, no, they can, but I wonder if, I don't know. Yeah, I don't know. It's just really, I think everyone's kind of overwhelmed with how many fucking things you gotta manage. Yeah. It's just too much.

Iain Thomson

And this is one of the things they're relying on. It's just, because you're right, we've got so many of these things. I probably shouldn't. I mean, I don't know about you guys, but corporate policy is I have to change my password every few months. And that's just a nightmare.

Graham Cluley

Obviously, there are automated systems already used by vulnerability researchers to find vulnerabilities.

Iain Thomson

Exactly.

Graham Cluley

To find security holes. And we've even seen recently things like ChatGPT where you can give it a lump of code.

Iain Thomson

Yeah.

Graham Cluley

And say to it, tell me where the problem is. And it'll say, oh, there's a vulnerability here. Yeah.

Iain Thomson

Now, admittedly, Stack Overflow banned them temporarily because they got it wrong so many times. But that technology is getting scarily smart now.

Graham Cluley

Yes. Yeah.

Carole Theriault

It's only still nascent.

Iain Thomson

Well, as you say, though, there are already tools to do this. One of the points they made in the report is that when it comes to an AI going around internally in a network and avoiding security software, there are no datasets for that as yet. There's not even that much academic research. There's only been— I think there's a research center in Israel from 2020 and one at Carnegie Mellon from 2019 looking at this stuff. So there's no AI training sets, but that day will come. I should imagine several governments are working on that at the moment. Isn't that a cheery thought to go into Christmas with?

Graham Cluley

Is there anything good that's coming from AI though? Is there a— I mean, if we were to balance the good and the bad, do you— it feels like we tell a lot of doom and gloom stories regarding artificial intelligence. Well, you do, Carole. Yes, all the time.

Carole Theriault

We tell doom and gloom stories about technology in general, Graham.

Graham Cluley

My story was very, very positive. If you were to fall down the lavatory, then maybe the robot would actually come to your rescue. Maybe it would send out a distress call. It's only going to require a new update, I'm sure, to the Roomba to do that.

Carole Theriault

Alright, so now definitely do poop with your Roomba with the door open.

Iain Thomson

Well, didn't you hear that? I don't know if you heard that story this week that happened with someone's Apple iPhone. This was a remarkable case down near Los Angeles. Just, it was local news. A couple were driving along, lost control of the vehicle, fell 300 feet into a gorge. Thanks to the miracle of airbags and proper seatbelts, they survived, but they were in the middle of nowhere. And that iPhone detected the crash and said, do you want to contact the satellite? And they're like, what? Okay. And they told it, the iPhone said, orientate to here. That got the message out and they were picked up and taken to hospital. But so yeah, sorry, small side note on local news here from the Bay Area. Happy story for Christmas.

Graham Cluley

That's what we need. Some cheer finally. Thank goodness. Carole, I'm sure you're going to cheer us up with your story as well.

Carole Theriault

I am. I have a Christmassy tale.

Graham Cluley

Okay.

Carole Theriault

But with a warning. All takes place in Ireland. And this year, according to local media, there are concerns that Ireland, the Emerald Jewel, may get slammed by the Beast from the East. Not a fanged mythical creature thing who will prowl the streets instead of Santa Claus.

Iain Thomson

Vladimir Putin?

Carole Theriault

Yeah, but more of a weather roller coaster. So it has something to do with the North Pole winds being driven down via the Atlantic, plus the barrage of low pressure. So wind, heavy rain, hail, frost, ice, wintry showers, the whole thing. And while this is music to the ears of probably Irish kids and snow lovers like me, right, who would kill for a white Christmas—

Iain Thomson

You can take the woman out of Canada, but you can't take the Canadian out of the woman. Exactly.

Carole Theriault

I love a white Christmas. Cabbies are likely to see a big bump in ride requests, right, when the weather— Yeah. So it's the perfect cabbie trifecta because you have bad weather, you have holiday festivities.

Iain Thomson

Yeah.

Carole Theriault

And that means you have many merry people who will need lifts to and from places. But the problem is, since the pandemic, it can be kind of hard to land a cab in Dublin. There are fewer drivers and it can be a nightmare for anybody to secure one. Right, this is all from the Irish Independent, which may be why the Gardaí are warning their Dublin residents of a targeted taxi scam that has managed to pilfer hundreds and hundreds of thousands of pounds from their victims. And so, okay, maybe you can have a go at guessing it. So it involves taxis, right? I'll give you a sentence from an article. I'll just give you the one sentence to see if you guys can backward work it. The criminals have worked out how to beat facial recognition software on mobile phones, which they use to empty their targets' bank accounts.

Iain Thomson

Are they hacking the taxi driving service?

Carole Theriault

No, but good one.

Graham Cluley

Are there cameras in the taxi cabs?

Carole Theriault

No.

Iain Thomson

Oh, that's a— okay.

Carole Theriault

It's a pretty low-tech approach, actually. It's kind of fun.

Graham Cluley

Is it a cutout of people's faces? Are they wearing reindeer ears?

Iain Thomson

Using their Facebook photos?

Carole Theriault

Okay, no, no, I have to— So this is the game plan for the attacker according to the paper. So you hit up a busy pub.

Iain Thomson

Mm-hmm.

Graham Cluley

Yeah.

Carole Theriault

It'll be full of festive cheers and work parties and family gatherings. And you eyeball the target. You might choose your target because you see them pay with their phone, for example.

Graham Cluley

Right.

Carole Theriault

Yeah. So then you might scooch up close to them, but in a non-invasive sort of way, and watch them really closely. Shoulder surfing. Shoulder surf them. That's a hard word for me to say.

Graham Cluley

Shoulder surfing. Yeah.

Carole Theriault

Shoulder surf. Okay. In a busy pub, it might be pretty easy, right? We have all been in that situation. Yeah. Not since the pando, but I bet this year that's all happening, right?

Graham Cluley

Yeah.

Carole Theriault

And you do this because you're waiting to get their phone's passcode.

Iain Thomson

Oh, you're right, old-fashioned.

Carole Theriault

Yeah, old-fashioned.

Iain Thomson

Okay, I mean, that's the ATM attack that's very analog.

Graham Cluley

Yeah.

Carole Theriault

Okay, then the scammer then has to wait, right? You got to wait for your target to want to head out. Perhaps, no, tries his trusty taxi app, but guess what? No cars available for the next hour or whatever. So what do you do if you're in Dublin? You'll go outside and maybe try and hail a cab, right? You never know.

Graham Cluley

Yeah.

Carole Theriault

Meanwhile, around the corner, a bogus taxi with a fake number plate and a little fake light on the top, maybe even a green smelly Christmas tree dangler on the mirror. It is traditional, a way instruction from his scammy cohorts to tell him, Paddy, you know, get your skates on.

Iain Thomson

Oh, Jesus, you can say that?

Graham Cluley

No, I'll be— I can't believe you said Paddy, Carole. That was outrageous.

Iain Thomson

Blatant racial slur. It's helping. I feel abused.

Carole Theriault

Okay, and the fake cabbie's job is to do a drive-by, to be a beacon in the snowstorm, blinking on its little legit-looking light to attract the target, right? In one case, the victim says the fake cab actually honked the horn sort of a yoo-hoo way and then waved him over.

Iain Thomson

Interesting.

Carole Theriault

Of course, the target is going, oh God, how amazing am I?

Graham Cluley

Great, I've got a cab.

Carole Theriault

Yeah, I'm so lucky, this is amazing. And they hop in, and what do they do next?

Graham Cluley

I don't know, how do they steal the money? What's this?

Iain Thomson

We'll just give them a taxi ride.

Carole Theriault

Wait, wait, wait, what are you going to do when you get in a cab?

Graham Cluley

You say, follow that cab quick and don't spare on the horses.

Carole Theriault

You give them your address.

Graham Cluley

You give them your address.

Carole Theriault

Probably heading home, don't you?

Graham Cluley

Yes.

Iain Thomson

Okay.

Graham Cluley

All right.

Carole Theriault

Yeah.

Graham Cluley

Right.

Iain Thomson

Ooh, is this the long con?

Carole Theriault

Right. Okay. So wait, just wait. Okay. But that doesn't seem to be their claim because during the drive, the criminal cabbie has to somehow get his mitts on your phone. Right? So how do you go about doing that? So in one instance, the scammer brought the target close to the destination but then asked to double-check a route. Could he borrow the phone so he could double-check a route on Google Maps? Ah, guy hands over the phone. Cabbie then drops it into the passenger side footwell and claims he can't get it because of his bad back.

Graham Cluley

I'm sorry. I'm really sorry.

Carole Theriault

So he says to the target, can you come get it? Can you come out to the front and come get it in the footwell? And the target's like, fuck yeah, that's my phone. So he jumps out of the backseat. Car zooms off. So the phone is now in the cabbie's hands. They, in this instance actually, if they asked for Google Maps, you know, the target would have opened it for them. But the cab, they don't want to just get on the phone. They also want to get access to the bank accounts. So the first step is to reset facial ID to your own face, to the scammer's face. And then once in, they head to the banking apps and try and reset that facial ID. Because lots of the banking apps have facial ID required. And you're almost there because then banks will often ask for a PIN if you try and reset the facial ID for an extra layer of protection. And the key here is that people seem to use the same fucking ID.

Iain Thomson

Yeah, of course.

Carole Theriault

That they were shoulder surfing when they first saw how to get into the phone.

Graham Cluley

Yeah.

Iain Thomson

That's a really complex effort to—

Graham Cluley

It's quite elaborate.

Iain Thomson

Effort to reward, I've got to say. But part of me is just like, well, respect.

Carole Theriault

It's a great story.

Iain Thomson

Oh yeah, it is a great story. It's just like, also I've got to say as an American, the idea that your bank is taking that level of security, I mean, and it's just over here, it's a joke. But yeah.

Carole Theriault

Oh, really, eh?

Iain Thomson

I mean, don't even get me started. When I first moved over here, Chase weren't allowing symbols in passwords. Just numbers and letters, uppercase and lowercase. Anyway, but I mean, it's a really interesting contrast of social engineering and, you know, just—

Carole Theriault

And low level. Like, you know, you don't have to be a genius here. Like, you know, this is not tech genius. This is just good old-fashioned fake cabbie, you know? Hey, you need a cab? You need a cab? Jump in.

Iain Thomson

Well, this is it. The shoulder surfing job's got to be great though, because you've just got to hang around a pub looking over people's shoulders. It's just like, oh great, I can drink on the job.

Carole Theriault

I tell you what, the best place to shoulder surf is on places like buses, trains, and planes. People are unbelievable. Like, they really feel like they're alone in their seat, and it's unbelievable, especially if you sit on the aisle. Be careful.

Iain Thomson

This is why the plane flight from DEF CON in Las Vegas back here is fantastic, because you've got a bunch of people on your laptops. It's just like, oh no, I have a weak bladder. I need to go and walk up and down the aisles and just see what everyone's doing for a while.

Carole Theriault

That's why you never work on a plane.

Iain Thomson

Oh God, no.

Carole Theriault

So, okay, moral of the story, use long PINs. Harder for a scammer to remember if you have to type it in.

Graham Cluley

Maybe fingerprint ID or facial ID on your banking apps rather than just a number.

Carole Theriault

They did have that and they changed it, right? They were able to change it. So—

Graham Cluley

Oh, I see.

Carole Theriault

Yeah.

Graham Cluley

Well, definitely, definitely have different PINs then for your apps.

Carole Theriault

Definitely different PINs.

Graham Cluley

Yes, you do have a PIN there.

Iain Thomson

Always good advice.

Carole Theriault

Use a password manager to manage all that stuff.

Iain Thomson

And then just make sure the password manager isn't cracked.

Carole Theriault

Yeah.

Iain Thomson

Because then the game's over. But yeah.

Carole Theriault

Maybe take a picture of the cabbie before you get in as a precaution, you know? Just 'cause then it just goes to the cloud.

Graham Cluley

Oh, they're gonna be fine with that. They're not gonna find that aggressive, are they?

Carole Theriault

They might drive off and say, "I don't want this guy in my cab." You know, he's a waster, and you might think, "Oh, you damn cabbie!" But you might have just saved yourself. And what about shoulder surfing? If you ever think someone's shoulder surfing you, why not just accidentally toss your drink over your shoulder and say, "Oh, sorry, it's just for luck." What kind of bar fight are you gonna kick off, Carole, in Dublin?

Graham Cluley

What do you mean?

Carole Theriault

They're lovely people. You just say sorry.

Graham Cluley

Is this how you operated?

Carole Theriault

Wow.

Iain Thomson

No, you can't do that, particularly in an Irish— Only in England, only in Britain and Ireland is glass both a noun and a verb. You don't want to get in trouble to that kind of fight.

Carole Theriault

That's true.

Iain Thomson

So whenever you go to a pub in the UK, it's just a little club in the UK. It's just like, here's your plastic glass. It's just white wine. Oh yeah. Okay.

Graham Cluley

Fair enough.

Carole Theriault

It's like being in an airport with your little baby knife.

Graham Cluley

Listeners know that a password manager is an important tool for generating and saving secure credentials for each of your online accounts. And podcast sponsor Bitwarden makes it easy to stay secure and for businesses to share logins with team members and departments. Now, what's nice is that it's open source with published third-party security audits. Bitwarden is transparent and secure. It utilizes end-to-end and zero-knowledge encryption with source code that can be scrutinized by all. And the team at Bitwarden are always introducing new features to make your life easier as well as more secure. They've just introduced passwordless login for the Web Vault, meaning you can authenticate into the Web Vault using your Bitwarden mobile app instead of entering your master password. Learn how Bitwarden can help you do business faster and more securely at bitwarden.com/smashing and start a free business plan trial today. That's bitwarden.com/smashing. And welcome back. And you join us at our favorite part of the show, the part of the show that we like to call Pick of the Week.

Carole Theriault

Pick of the Week. Yeah.

Iain Thomson

Oh, Pick of the Week.

Graham Cluley

Pick of the Week is the part of the show where everyone chooses something they like. Could be a funny story, a book they've read, a TV show, a movie, a record, a podcast, a website, or an app. Whatever they wish. Doesn't have to be security-related necessarily.

Carole Theriault

Better not be.

Graham Cluley

Well, my pick of the week this week and my last pick of the week of the year is a movie, a short movie which comes from Spain. It came out 50 years ago this month, I learnt. So I thought I'd try and be on trend.

Iain Thomson

Okay.

Graham Cluley

Because people might want to enjoy it. Yes, it first aired on 13th of December, 1972 on Televisión Española, 35 minutes long. It is La Cabina. La Cabina, if you weren't aware, is Spanish for a telephone box. And in this movie, it's a little bit of a scary movie, a little bit frightening. It's all about a man who gets in a telephone box and gets trapped, and he can't get out of the telephone box.

Carole Theriault

And he really needs to poop. And— No? Okay. I'm just trying to precede and get my mind ready.

Iain Thomson

I thought Colin Farrell was involved in that, but—

Graham Cluley

Despite the attempts of passersby to help him, he cannot be freed from this telephone box. Now, in the chance that some people may actually choose to watch this, I'm not going to reveal what happens next.

Carole Theriault

He's still in there.

Graham Cluley

Well, I'm not saying anything. But I do believe that there is now a statue of the actual— So in Spain, this is apparently a famous movie. When I say famous, famous amongst people of my sort of age who are interested in old movies. So there's now a statue of the telephone box in the place where it was filmed, which seems rather scary to me. And my advice, do not go in it. So my pick of the week is La Cabina, and you can watch it on the tube of you. And I will put a link in the show notes.

Carole Theriault

God, that's actually more frightening, isn't it? Being said like that. The tube of you is exactly what it is.

Iain Thomson

The tube of you. That doesn't sound good, no.

Graham Cluley

Iain, what's your pick of the week?

Iain Thomson

Well, something that's not going to get me put on a police register, certainly, but— No, I mean, for me, it's the new year, and we've got another trip around the sun to do, and I was thinking of the future.

Graham Cluley

Hang on a moment, hang on a minute, Iain. Surely that can't be your pick of the week. That's your pick of next week.

Iain Thomson

Well, okay, fair enough.

Graham Cluley

Sorry to pull you up on a technicality at this point.

Iain Thomson

Okay, well, I would say it's a time to think about the passing of time then. How does that—

Carole Theriault

Ignore him. Ignore him. Yeah, just ignore him.

Iain Thomson

And I've just been revisiting one of my favourite books, The Last and First Men by Olaf Stapledon. Okay, it's written in 1930 and it covers basically the evolution of humanity from current day in 1930 to around a few billion years later when, oh well, I won't spoil the ending, but some things get interesting. But this is a book which inspired Arthur C. Clarke. It's been, it's one of the more popular ones on Desert Island Discs as the book that they pick. And it's available on Project Gutenberg free of charge because it's so old. I would say it's, if you do read it, ignore the first 50 pages. Future prediction is terribly hard. And he kind of gets that wrong, particularly the Second World War thing.

Graham Cluley

Okay.

Iain Thomson

But once you get into the second generation of man and then the third of humanity and then the third and fourth and fifth and sixth and all the way up to 18th, it becomes very interesting. And it's a good joyful book to read at the new year because you know that we're going somewhere one way or the other.

Carole Theriault

I can see there's also a movie of it. I don't know. I've never crossed paths with this book.

Iain Thomson

It's one of those books which a lot of people who work in the tech industry or who work in science have read and love. It's just, but very few people have heard of it. As I say, the first 50 pages are against it, but once you get past that, then yeah, he's a very interesting character, a British bloke, conscientious objector during the war, but then joined up. And Rhodes was the science fiction sort of bestseller of his day, but his day was, you know, the 1920s and '30s, so no one remembers now.

Graham Cluley

Well, you've changed all of that today. Thank you very much. Carole, what is the final pick of the week for the entire year?

Carole Theriault

Yes, the last pick of the week for 2022 is a book that I just finished called The Other Side of Night by Adam Hamdy. It is a thriller, and I should say it's a book I experienced rather than read because I just don't seem to read anymore since I got into podcasts and art. It's I have to save my eyes for looking at audio waves and art stuff. So I've been delving into audiobooks recently, and this one blew me away. So just basic premise because there's a lot of twists and turns and I don't want to ruin anything, but it's a disgraced police detective named Harriet. And she's now suddenly with a lot of time on her hands. And she hits the library. And she's looking at this book, she's reading this book, and there's this frightening little scribble in the book margin that leads her into this really windy investigation to find out what happened to the person who penned the scribble. Like, who are they? What happened to them, etc.? And basically, a simple investigation becomes something entirely different. And the story ends up somewhere utterly unguessable, and gloriously fitting. It's a really beautiful concept, and it's written with honesty and heart and grace. But it's kind of also a meta thriller with really big ideas. So I loved it and snarfed it up in a weekend. And I would say it's the perfect book to drown in if you're having a quiet Crimbo or holiday, or if perhaps you're visiting the in-laws and prefer to hide away than help make the bread sauce. For example.

Iain Thomson

I'm so with you on that.

Graham Cluley

Sales have just rocketed.

Carole Theriault

So my pick of the week, and it's actually also on the New York Times best thrillers of 2022. So that's where I actually heard of it initially. So The Other Side of Night by Adam Hamdy, and highly recommended.

Iain Thomson

Marvelous.

Graham Cluley

Can I say we've all done very, very well with our cultural picks of the week this week. We've had two books and obviously a Spanish— well, maybe my one wasn't— a Spanish movie about someone being trapped in a telephone box. But anyway, I feel like we've raised the tone and that's a good note to end on. And it just about wraps up the show. In fact, it wraps up the show for 2022. We will be back in the second week of January, January 2023. Now to make—

Iain Thomson

Because you would get proper Christmases over there, right?

Graham Cluley

We have proper breaks over here. Now to make sure you do get that episode as soon as it's released, follow Smashing Security in your favorite podcast app such as Apple Podcasts, Spotify, and Google Podcasts, and you'll never miss another episode. Iain, I'm sure lots of our listeners would love to follow you online. What's the best way for folks to do that?

Iain Thomson

Well, it used to be Twitter, and I am still @IainThomson on Twitter, although I'm mainly restricting myself to posting very little other than marking the burning of Rome, as it were. But you can get me at Mastodon social using the same name. And I apologize in advance for the spelling of Iain and Thomson, but I have Scottish heritage and my parents and I have had words about this. But yeah, if I ever have a kid, they're going to be called Dave or something like that so that no one misspells my name.

Graham Cluley

So it's Iain with two I's and Thomson without a P, I think.

Iain Thomson

Without a P at Mastodon Social.

Graham Cluley

Fantastic. And you can follow us on Twitter at Smashing Security, no G, Twitter allows to have a G, although there's lots of changes happening on Twitter at the moment, who knows? But we've also got a Mastodon account.

Carole Theriault

Yay!

Graham Cluley

So you can find that easiest way is to go to smashingsecurity.com/mastodon and that'll take you right there. And you can also look up the Smashing Security subreddit.

Carole Theriault

Massive shout out to this episode sponsor, Bitwarden and to our wonderful Patreon community. It's thanks to them all that this show is free all year. For episode show notes, sponsorship information, guest lists, and the entire back catalog of more than 302 episodes, check out smashingsecurity.com.

Graham Cluley

Until next year. Cheerio, bye-bye.

Carole Theriault

Bye. Happy New Year.

Iain Thomson

Happy New Year.

Graham Cluley

Graham Cluley. Thank you very much, Iain.

Carole Theriault

Yeah, that was fun.

Iain Thomson

No problems. That was a lot of fun.

Carole Theriault

Can you go back to bed now or do you have to go to work?

Iain Thomson

Oh God, no, no. My workday is 8 till 6. So yeah, I'm clocking on in a few minutes. But yeah, it's the American — it's not like Britain.

Carole Theriault

Listeners, despite us still living in a crazy, unpredictable world, we wish you and your loved ones a safe and happy holiday. See you in a few weeks.

Hosts:

Graham Cluley:

Carole Theriault:

Guest:

Iain Thomson – @iainthomson

Episode links:

Sponsored by:

  • Bitwarden – Password security you can trust. Bitwarden is an open source password manager trusted by millions of individuals, teams, and organizations worldwide for secure password storage and sharing.

Support the show:

You can help the podcast by telling your friends and colleagues about “Smashing Security”, and leaving us a review on Apple Podcasts or Podchaser.

Become a Patreon supporter for ad-free episodes and our early-release feed!

Follow us:

Follow the show on Bluesky at @smashingsecurity.com, or on Mastodon, on the Smashing Security subreddit, or visit our website for more episodes.

Thanks:

Theme tune: “Vinyl Memories” by Mikael Manvelyan.
Assorted sound effects: AudioBlocks.


Graham Cluley is an award-winning keynote speaker who has given presentations around the world about cybersecurity, hackers, and online privacy. A veteran of the computer security industry since the early 1990s, he wrote the first ever version of Dr Solomon's Anti-Virus Toolkit for Windows, makes regular media appearances, and hosts the popular "Smashing Security" podcast. Follow him on TikTok, LinkedIn, Bluesky and Mastodon, or drop him an email.

3 comments on “Smashing Security podcast #303: Secret Roomba snaps, Christmas cab scams, and the future of AI”

  1. AnonPerson

    Looks like the latest episode doesn't have the "play audio" option in several of my podcast apps (for the RSS feed) :(

    1. Graham CluleyGraham Cluley · in reply to AnonPerson

      If you’re using the official Smashing Security RSS feed you shouldn’t have a problem.

      https://www.smashingsecurity.com/rss

      1. AnonPerson · in reply to Graham Cluley

        Ah hah perfect, thank you! Looks like my link was /feed instead of /rss – replacing it got it to work perfectly!!

What do you think? Leave a comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.