Episodes

  • Rethinking Online Anonymity with Lance Cottrell
    Nov 20 2024

    In a world of cybersecurity and online privacy, anonymity seems to be the key. VPNs are often promoted as the cure-all to our internet needs. Let’s talk about some of those misconceptions.

    Today’s guest is Lance Cottrell. Lance founded Anonymizer in 1995 and is an internationally recognized expert in cryptography, online privacy, and internet security. He is the principal author on multiple internet privacy and security technology patents. Lance stayed on as Chief Scientist as Anonymizer was acquired by Intrepid, and now advises start-ups through his platform.

    Show Notes:
    • [1:09] - Lance shares his background and how he spent the start of his career and into founding Anonymizer.
    • [3:03] - To continue destigmatizing being a victim of a scam, Lance shares his own experience as a victim himself.
    • [5:38] - In-person scammers are very believable. They learn through building a relationship the things that you want.
    • [9:47] - There are two reasons why people commit treason - revenge and justice.
    • [10:42] - Prior to founding Anonymizer, Lance had fantastic access to the internet in the early 90s and became involved in the open-source community.
    • [13:58] - Lance describes how Anonymizer did business-wise and where it capped.
    • [17:40] - There are different types of customers for Anonymizer, general consumers as well as government entities.
    • [20:30] - There were certainly times where someone would come to Anonymizer and they had done something that was really pretty dire.
    • [23:28] - Anonymizer was able to develop some new technologies that Lance describes.
    • [25:35] - If you need to trust someone, research who that someone is and understand if you can.
    • [27:11] - The biggest mistake is thinking your IP address is the important thing.
    • [29:19] - Actually achieving anonymity or pseudonymity and maintaining overtime is incredibly challenging.
    • [31:09] - Human behavior tends to give away anonymity.
    • [33:47] - People don’t think anywhere near enough on the threat model.
    • [34:58] - When are VPNs actually beneficial?
    • [37:32] - Be very specific about what you want to protect.
    • [40:05] - Obsession and trying to run your life around trying to be anonymous is not helpful.
    • [41:41] - Lance discusses some of the interesting aspects of the psychology of criminals.
    • [43:10] - Lance shares some parting advice and the basic things to do to stay protected.

    Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.

    Links and Resources:
    • Podcast Web Page
    • Facebook Page
    • whatismyipaddress.com
    • Easy Prey on Instagram
    • Easy Prey on Twitter
    • Easy Prey on LinkedIn
    • Easy Prey on YouTube
    • Easy Prey on Pinterest
    • Lance Cottrell on LinkedIn
    • Lance Cottrell Website
    • Feel the Boot - The Science of Startups
    Show More Show Less
    44 mins
  • AI: Double-Edged Sword for Cybersecurity with Vincent LaRocca
    Nov 13 2024

    Cybersecurity is more crucial than ever. It’s essential that we proactively safeguard our data and recognize that no one is immune to attacks. We are all vulnerable. As malicious actors continually enhance their tactics, we must stay one step ahead by consistently improving our defenses.

    Today’s guest is Vincent LaRocca. Vincent is the CEO of CyberSecOp with the commitment to protecting sensitive data and mitigating cyber threats. With over two decades of experience, Vincent has successfully steered CyberSecOp to become one of the world’s fastest growing managed security providers, specializing in cybersecurity assessments, breach management, and risk management consulting.

    Show Notes:
    • [1:15] - Vincent shares his background and how he found himself working in cybersecurity.
    • [2:40] - Even the experts are vulnerable. Vincent shares an experience he had with fraud at his bank.
    • [4:16] - Cyber threat trends are moving to AI.
    • [6:19] - As consumers, we need to be aware of how AI is using our data and what we give it permission to have access to.
    • [8:19] - AI isn’t going anywhere. It will continue to grow and develop.
    • [9:16] - Threat actors are unfortunately usually one step ahead of defenses. They are using AI to exploit vulnerabilities.
    • [11:54] - AI gives threat actors even more reach. The number of incidents and scams are extremely high and will multiply.
    • [13:59] - Small organizations and business owners are hit pretty hard by breaches since they often do not have a cybersecurity team.
    • [16:09] - Vincent shares some of the traits and qualifications that are good to look for in cybersecurity professionals for small businesses.
    • [19:07] - Defenses are built against things that we know about, not things we don’t know about.
    • [21:27] - There are things that can be done that are free or more cost-effective.
    • [23:40] - There’s no point in putting a fancy lock on the front door if there’s nothing protecting the back door.
    • [27:06] - Even if an organization has invested in cybersecurity and knows how to keep data safe, if their partners or vendors do not, it means very little.
    • [28:31] - There are so many breaches that have happened that we don’t even know about and our data is out there mixed in with so much more.
    • [30:31] - We are a part of an AI revolution currently and the landscape of AI will be completely different in just a few years.
    • [33:58] - The tools for cybersecurity, including machine learning, are improving every day as well.
    • [37:09] - Don’t turn a blind eye and assume you can’t afford protection.

    Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.

    Links and Resources:
    • Podcast Web Page
    • Facebook Page
    • whatismyipaddress.com
    • Easy Prey on Instagram
    • Easy Prey on Twitter
    • Easy Prey on LinkedIn
    • Easy Prey on YouTube
    • Easy Prey on Pinterest
    • Vincent LaRocca on LinkedIn
    • CyberSecOp Website
    Show More Show Less
    38 mins
  • Understanding and Avoiding Triangulation Fraud with Soups Ranjan
    Nov 6 2024

    As consumers, we may realize the need to be vigilant by using two-factor authentication and password managers, but there are so many scams out there that can impersonate legitimate organizations, websites, and people. We really can’t let our guard down.

    Today’s guest is Soups Ranjan. Soups has over 18 years of experience in software engineering, data science, and risk management. He is the co-founder and CEO of Sardine. This behavior-infused platform offers fraud prevention, compliance, and payment solutions for various industries including banking, online marketplaces, FinTech, crypto, online gaming, and gift card exchanges. Previously, Soups led the Risk and Data Science teams at CoinBase, where he scaled the platform and enabled millions of users to buy, sell, and store cryptocurrency securely and efficiently.

    Show Notes:
    • [1:15] - Soups shares his background and information about his company, Sardine.
    • [4:30] - He has not been a victim of a scam online but did experience an in-person scam.
    • [6:57] - Sardine works with a diverse set of clients. Trends differ based on the industry. One major trend is an increase in triangulation fraud.
    • [9:07] - Once they have card details, they can pretty much do whatever they want with it.
    • [11:40] - Even on a contactless card, using tap-to-pay, be careful. Don’t hand over your device.
    • [12:43] - It is becoming increasingly difficult to verify the identities of merchants.
    • [15:21] - There is a big rise in scams as a result of the demand for real-time money transfers and exchanges.
    • [17:45] - Some scammers are instructing victims to install screen viewers and recording tools.
    • [19:50] - Machine learning is used to help protect clients.
    • [21:41] - There are intrinsic behaviors that Sardine monitors to watch for unusual activity.
    • [24:41] - Soups describes some of the other types of data that is observed in addition to behavior.
    • [27:08] - Soups explains 3D Secure and what the benefits of this system are.
    • [30:41] - Dollars lost to scams have far surpassed the dollars lost to fraud.
    • [33:37] - The United States is behind in regulatory measures.
    • [35:59] - It is best to work with banks that take fraud and scams very seriously.
    • [37:15] - Soups lists some of the red flags and be on the lookout for.
    • [39:44] - It is extremely important to protect your email address in the same way you protect your bank account.

    Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.

    Links and Resources:
    • Podcast Web Page
    • Facebook Page
    • whatismyipaddress.com
    • Easy Prey on Instagram
    • Easy Prey on Twitter
    • Easy Prey on LinkedIn
    • Easy Prey on YouTube
    • Easy Prey on Pinterest
    • Soups Ranjan on LinkedIn
    Show More Show Less
    42 mins
  • Finding Small Business Fraud with James Ratley
    Oct 30 2024

    There are a shocking amount of businesses that ultimately fail because of fraud. Many managers and business owners are unaware of their losses because they do not have the systems in place to look for fraud and it may not be their primary concern.

    Today’s guest is James Ratley. Jim graduated from the University of Texas at Dallas with a bachelor’s degree in Business Administration. In 1971, he joined the Dallas Police Department as a police officer. He was on numerous task forces with a concentration on major fraud cases. He joined a major forensic accounting practice and was in charge of fraud investigations.

    In 1988, he was named the Program Director of The Association of Certified Fraud Examiners and in 2006, became the President. In 2011, he became the CEO and he retired in 2018 after 30 years there. James has been an adjunct professor, published author, and named by Accounting Today as one of the top influencers multiple times.

    Show Notes:
    • [1:14] - James shares his background and the way his career panned out over 30 years.
    • [3:35] - When the ACFE was established, there was no information or education around it at all.
    • [5:09] - The average organization loses 5% of their revenue to fraud. Out of every ten people hired, statistically, six of them will steal from you.
    • [6:46] - Fraud can be prevented and strategies to reduce fraud are typically inexpensive.
    • [8:40] - It’s important for business owners not to be afraid to call it fraud.
    • [10:25] - Fraud perpetrators believe they deserve what they’ve taken.
    • [13:26] - It’s important for businesses to have strong management and leadership. Training is crucial.
    • [14:18] - James discusses the most common types of fraud and how even the seemingly minor things could be detrimental.
    • [18:24] - Fraud perpetrators are really good at hiding what they are doing and making the business owners believe it could never be them.
    • [20:15] - Another strategy is to separate tasks out and be strict about them.
    • [21:37] - Surprise cash counts is another good strategy.
    • [23:13] - There are no small frauds, only frauds that have not had time to reach maturity.
    • [25:44] - You impact rationalization through education.
    • [29:16] - James lists some of the red flags that could indicate something more going on.
    • [31:31] - There should be policies and regulations that purchasing officers are held to.
    • [36:30] - Auditors must be completely independent.
    • [40:10] - Some business owners will deny the problem is happening because it is hard to deal with and accept that someone they trust could be stealing.
    • [44:35] - Many small organizations go out of business due to operating at a loss. Most of the time this is because of fraud.
    • [47:25] - Never judge someone by the standards you have for yourself.
    • [51:12] - Something to remember is that most fraudsters will steal in even numbers.
    • [53:11] - In most cases that James has worked, the manager had seen all the signs, but never thought anything about it.

    Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.

    Links and Resources:
    • Podcast Web Page
    • Facebook Page
    • whatismyipaddress.com
    • Easy Prey on Instagram
    • Easy Prey on Twitter
    • Easy Prey on LinkedIn
    • Easy Prey on YouTube
    • Easy Prey on Pinterest
    • ACFE Website
    Show More Show Less
    56 mins
  • Truth and Lies with Mark Bowden
    Oct 23 2024

    Now that so much of our communications are digital, such as texts, emails, and chats, we miss out on the tone and facial expressions to help us understand the intent and content in communication. It’s important to know ourselves well enough to know what areas we’ll be more easily influenced and are susceptible to being deceived. The greater our desire for something to be true, the easier it is for us to be scammed.

    Today’s guest is Mark Bowden. Mark is a world-renowned body language expert, keynote speaker, and best-selling author. He is the founder of the communication training company, TruthPlane. Mark is also a member of The Behavior Panel on YouTube.

    Show Notes:
    • [1:08] - Mark shares his background and what motivated him to specialize in human behavior.
    • [2:34] - There are parts of the brain that are activated when we first meet someone new.
    • [3:56] - Think about how many people you see on a regular day. Some you will notice and some you will not.
    • [7:03] - There are certain parts of the brain that can overwrite natural instinct.
    • [10:02] - Mark demonstrates how body language changes when there is perceived risk.
    • [14:50] - Body language signals can be perceived inaccurately. People can also change their body language to send different signals.
    • [17:15] - So many signals that our brains rely on in communication disappear when we cannot see the person we’re talking to.
    • [19:16] - Mark gives an example of how the human brain perceives the bait of a scam.
    • [22:48] - The first step in critical thinking is to suspend judgment.
    • [25:58] - “You can only con a greedy man.” Think about what you want so much that if it were offered, you lose your sense of judgment.
    • [28:33] - If anyone ever tells you that something seems like it isn’t true, suspend judgment and look into it.
    • [30:32] - It’s a risky world. There are people who have dedicated their lives to deceiving others.
    • [35:13] - Part of critical thinking is asking other people whom you trust about what they think.
    • [39:56] - Sometimes we will set people up to see how they will respond.
    • [43:11] - It is best to have an open mind and be willing to see things for what they are over what you want them to be.

    Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.

    Links and Resources:
    • Podcast Web Page
    • Facebook Page
    • whatismyipaddress.com
    • Easy Prey on Instagram
    • Easy Prey on Twitter
    • Easy Prey on LinkedIn
    • Easy Prey on YouTube
    • Easy Prey on Pinterest
    • TruthPlane Website
    • Mark Bowden on YouTube
    • The Behavior Panel on YouTube
    Show More Show Less
    46 mins
  • The Update That Broke America with Gabe Dimeglio
    Oct 16 2024

    Many industries are reliant on software and if the software becomes corrupt or an update fails, it may require hands-on support. Do you have your infrastructure set for repair and recovery?

    Today’s guest is Gabe Dimeglio. Gabe is a 20-year veteran of information technology and security for private and public sector organizations. He is a results-driven leader, specializing in security services and solutions for mission-critical, complex enterprise platforms. His expertise includes strategic consulting services, risk analysis/risk mitigation, and compliance.

    Mr. Dimeglio serves as Vice President & Executive Advisor, Security, Office of the CTO at Rimini Street. He is responsible for oversight of the GSS organization that provides tailored consulting and advisory security services to prospects and clients, in collaboration with Rimini Street sales, client engagement, and retention functions.

    Show Notes:
    • [1:18] - Gabe shares his background and what he does in his roles at Rimini Street.
    • [2:38] - Anyone can be a victim of a scam. That includes Gabe.
    • [4:03] - Scams are very sophisticated and techniques have come a long way in the last decade.
    • [5:23] - Gabe describes what happened with the update that shut down much of the United States’ systems and infrastructure.
    • [8:30] - To complicate things, the platform could not be restarted with this update in effect.
    • [10:42] - Updates are sideloaded continuously and are processed by this kernel driver. The thought process is interesting because it has happened before.
    • [12:37] - This was the biggest problem caused by Crowdstrike.
    • [14:47] - One mistake out of 10,000 updates is a low error rate, but there is a lot of reputation damage done in this event.
    • [16:50] - In the case of Crowdstrike, turning off auto-update was not an option.
    • [18:43] - Any time software, programs, or data are introduced, you’re also introducing risk.
    • [21:04] - Part of the solution to fixing this massive problem was hands-on support on every box.
    • [26:13] - One problem is that there are some industries where technology is very outdated.
    • [27:23] - People are selling their solutions and the solutions are cloud-managed. This is scary due to frequent cloud breaches.
    • [31:10] - There are still businesses that have no security professionals or teams managing client data and safety.
    • [32:53] - The skills gap is crushing most businesses.
    • [35:03] - Security has come a long way, even if there are still areas of lack.
    • [37:01] - For the last couple of years, security has been something that there is a budget for in most businesses.
    • [40:49] - Don’t ever let anyone convince you to shortcut anything.

    Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.

    Links and Resources:
    • Podcast Web Page
    • Facebook Page
    • whatismyipaddress.com
    • Easy Prey on Instagram
    • Easy Prey on Twitter
    • Easy Prey on LinkedIn
    • Easy Prey on YouTube
    • Easy Prey on Pinterest
    • Rimini Street Website
    Show More Show Less
    43 mins
  • A Lesson in Crisis Management with Jeremiah Grossman
    Oct 9 2024

    It’s not always easy to determine the value of digital assets. The potential of overestimating or undervaluing your data can make it difficult to establish how much protection you need for a cyber intrusion.

    Today’s guest is Jeremiah Grossman. Jeremiah has spent over 25 years as an InfoSec professional and hacker. He is the Managing Director of Grossman Ventures. He is an industry creator and founder of White Hat Security and Bit Discovery. He has his black belt in Brazilian Jiu-Jitsu and is an avid car collector.

    Show Notes:
    • [0:53] - Jeremiah shares his background and what he does as the managing director of new venture capital, Grossman Venture.
    • [1:55] - When he was 24, Jeremiah’s business was victimized by a data breach.
    • [5:30] - This experience taught him that if you treat your customers with integrity and have their best interests in mind, they will keep doing business with you.
    • [7:43] - These things happen to countless businesses. It is important to keep customers and clients informed.
    • [10:27] - Cybercrime is one of the only crimes where the victim doesn’t always know they’re a victim.
    • [13:30] - When it comes to solving these problems, we have to narrow in on the problems that are worth solving and then work for a solution.
    • [14:53] - Doing an asset evaluation is a good starting point. There is no algorithm to determine the value of digital assets.
    • [19:18] - What role does AI play in this and what should people be wary of?
    • [20:31] - How do we raise the cost on the adversary?
    • [23:12] - There are ways to bait adversaries as well which is an inexpensive solution.
    • [25:17] - These days, adversaries are nowhere physically near the data. They access it all through digital means.
    • [27:28] - Jeremiah is optimistic about AI and in his perspective, AI is a tool that will help us determine solutions.
    • [28:07] - Currently, cyber insurance has become compulsory.
    • [30:48] - Jeremiah explains how things work in venture capital and the problems that are common.
    • [34:11] - There are many things that we can do better in this space.
    • [35:46] - Jeremiah shares advice for small and medium-sized businesses.

    Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.

    Links and Resources:
    • Podcast Web Page
    • Facebook Page
    • whatismyipaddress.com
    • Easy Prey on Instagram
    • Easy Prey on Twitter
    • Easy Prey on LinkedIn
    • Easy Prey on YouTube
    • Easy Prey on Pinterest
    • Jeremiah Grossman’s Website
    • Jeremiah on Twitter
    Show More Show Less
    39 mins
  • Pig Butchering Is Getting Worse with Erin West
    Oct 2 2024

    Pig butchering is worse than just manipulating someone and taking their money. It leaves them with emotional anguish. Once their finances have been drained, they lose their financial security and they no longer trust people. Today’s guest is Erin West. Erin has been with the County of Santa Clara for 26 years and is a Deputy District Attorney. She specializes in cryptocurrency investigations and prosecutions.

    Show Notes:
    • [0:46] - Erin shares her background and what her role is as a Deputy District Attorney in Santa Clara County.
    • [3:20] - Five years ago, Erin found herself working on prosecutions regarding SIM swapping and cryptocurrency hacks.
    • [4:35] - The emotional impact of “just a financial crime,” is staggering.
    • [7:38] - You never know who around you is a victim of some of these crimes.
    • [8:18] - Erin describes the experience of being convinced to click a link herself.
    • [10:32] - Scammers will think about different things that would trigger someone into clicking a link.
    • [13:40] - Pig butchering involves building trust with a victim and showing them a false plush lifestyle.
    • [16:08] - A red flag is a text or social media message you may receive that seems misdirected or to a wrong number.
    • [19:21] - It feels like the right thing to do when we feel the need to respond to the scammer with a “you’ve got the wrong number,” but that’s how they start a conversation.
    • [22:29] - In many cases, scammers bulk text a massive amount of phone numbers. But some people are specifically targeted on social media.
    • [24:23] - Covid really accelerated this type of scam due to loneliness.
    • [25:40] - A misconception is that these scams target the elderly. But it is not based on age at all.
    • [27:03] - Unfortunately, law enforcement is not set up to be able to handle this type of crime.
    • [28:18] - Erin explains that law enforcement doesn’t tend to always lead with empathy when this type of crime is reported.
    • [30:12] - It is important to report the crime to local law enforcement, but there are other places that the crime can be reported to in addition.
    • [32:50] - Victims should be able to speak to a detective.
    • [34:33] - Victims should be very wary of third party recovery programs.
    • [37:26] - On the other side of things, a scammer could also be a victim of human trafficking and being forced to scam others.
    • [39:40] - Scams are being operated on a massive scale and have a front of a corporate business.
    • [41:14] - Initially, most of the cases seemed to have money moved out of the country. However, recently scammers have been found to be operating in the US.
    • [44:04] - There is some hope and opportunities in recent months where money laundering has been intercepted.
    • [46:41] - Progress in education and advocating for less victim shaming is moving in the right direction.

    Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.

    Links and Resources:
    • Podcast Web Page
    • Facebook Page
    • whatismyipaddress.com
    • Easy Prey on Instagram
    • Easy Prey on Twitter
    • Easy Prey on LinkedIn
    • Easy Prey on YouTube
    • Easy Prey on Pinterest
    • Erin West on LinkedIn
    Show More Show Less
    51 mins