WEBVTT

1
00:00:02.580 --> 00:00:10.080
<v Unknown>So these employees, they're drawing little boxes around things to say, this is a flower pot, this is a traffic cone, this is a coffee tender, whatever it may be. And yeah, but this, this is the reality.</v>

2
00:00:10.080 --> 00:00:17.579
<v Unknown>This trillion-dollar industry of AI, the actual truth is there's an awful lot of people who are having to do this. Smashing Security, Episode 466.</v>

3
00:00:17.579 --> 00:00:25.079
<v Unknown>Meta sees everything, copy fail, and a deepfake gets hired with Graham Cluley and special guest Paul Ducklin. Hello, hello, and welcome to Smashing Security, Episode 466.</v>

4
00:00:25.079 --> 00:00:32.579
<v Unknown>My name's Graham Cluley.</v>

5
00:00:49.780 --> 00:00:52.344
<v Paul Ducklin>And my name is Paul Ducklin.</v>

6
00:00:52.344 --> 00:00:54.267
<v Graham Cluley>Hello, Paul. Good to have you back on again.</v>

7
00:00:54.267 --> 00:00:59.603
<v Paul Ducklin>Hello, Graham.</v>

8
00:00:59.603 --> 00:01:04.939
<v Paul Ducklin>I always forget that when you do that pregnant pause, I'm supposed to give my name, even though I've done it many times before, I make the blunder every time.</v>

9
00:01:04.939 --> 00:01:14.076
<v Graham Cluley>You're not the only one. Sometimes I have to whisper and sometimes the whisper is edited out afterwards, say, "Say who you are." Yeah.</v>

10
00:01:14.076 --> 00:01:19.239
<v Paul Ducklin>So, oh no, if it gets that bad with me in any future episode, I'm happy for you to leave the stage whisper in</v>

11
00:01:19.239 --> 00:01:24.400
<v Paul Ducklin>because that will focus my mind for next time.</v>

12
00:01:24.400 --> 00:01:28.745
<v Graham Cluley>How has the world of cybersecurity been in the last Well, since we last spoke?</v>

13
00:01:28.745 --> 00:01:35.331
<v Paul Ducklin>Well, it has been a lot more of the same, hasn't it?</v>

14
00:01:35.331 --> 00:01:41.915
<v Paul Ducklin>More AI panics, more bugs, more patches, more social engineering attacks, more of everything.</v>

15
00:01:41.915 --> 00:01:47.536
<v Graham Cluley>It's always been that way, hasn't it? It's always been on that direction. You can't ever say, "Oh, it's been really, really quiet.</v>

16
00:01:47.536 --> 00:01:53.156
<v Graham Cluley>This whole cybersecurity business seems to be shutting down. Maybe we'll have to find ourselves a new job."</v>

17
00:01:53.156 --> 00:01:58.605
<v Paul Ducklin>We'll get into fishmongery. Well, phish with a PH would come after us, I'm sure.</v>

18
00:01:58.605 --> 00:02:08.604
<v Graham Cluley>Well, before we kick off, let's thank this week's wonderful sponsors, Action1, ESET, and Vanta. We'll be hearing more about them later on in the podcast.</v>

19
00:02:08.604 --> 00:02:18.604
<v Graham Cluley>This week on Smashing Security, we're not going to be talking about how a Brazilian firm that protects businesses from DDoS attacks was found to be helping a botnet that launched massive DDoS attacks. You'll hear no discussion of how Microsoft Defender started mistakenly detecting DigiCert root certificates as a Windows Trojan horse.</v>

20
00:02:18.604 --> 00:02:28.604
<v Graham Cluley>And we won't even mention how hackers managed to steal source code from cybersecurity giant Trellix. So, Duck, what are you going to be talking about this week?</v>

21
00:02:42.653 --> 00:02:48.734
<v Paul Ducklin>Graham, I am going to be talking about the latest BWAIN.</v>

22
00:02:48.734 --> 00:02:49.455
<v Graham Cluley>Oh?</v>

23
00:02:49.455 --> 00:03:00.917
<v Paul Ducklin>And when I say "BWAIN," it is bug with an impressive name. And if you've been looking at the IT media at all in the last week or two,</v>

24
00:03:00.917 --> 00:03:12.378
<v Paul Ducklin>you will probably have seen the words "copy fail." And I'm going to be talking about another reason why you should probably steer well clear of Meta's smart glasses.</v>

25
00:03:12.378 --> 00:03:19.878
<v Graham Cluley>Plus, we'll be talking about the danger of deepfakes with Jake Moore of ESET, who actually tricked a company into giving his deepfake a job offer after online interview.</v>

26
00:03:19.878 --> 00:03:27.378
<v Graham Cluley>All this and much more coming up in this episode of Smashing Security.</v>

27
00:03:27.378 --> 00:03:34.878
<v Graham Cluley>Well, we've got time now to chat about one of the sponsors of this week's show, Action1.</v>

28
00:03:34.878 --> 00:03:42.378
<v Graham Cluley>Now then, if you are a systems administrator managing endpoints every day, you've probably postponed patching at least once, not because you forgot, but because you didn't feel like gambling with uptime.</v>

29
00:03:45.305 --> 00:03:50.806
<v Joe>Meanwhile, the backlog grows, vulnerabilities pile up and patching stays stuck in manual mode.</v>

30
00:03:50.806 --> 00:03:56.963
<v Graham Cluley>Well, Action1 fixes that. Action1 is a cloud-native patch management platform for Windows, macOS, Linux, and third-party apps, all from one place.</v>

31
00:03:56.963 --> 00:04:03.122
<v Graham Cluley>No VPN needed.</v>

32
00:04:03.122 --> 00:04:07.064
<v Joe>Curious on how easy it is to start with Action1? Well, you can use it on your first 200 endpoints for free forever with no functional limits.</v>

33
00:04:07.064 --> 00:04:17.785
<v Graham Cluley>First 200 endpoints for free forever? That's bonkers. Incredible, Joe.</v>

34
00:04:17.785 --> 00:04:27.648
<v Joe>So if you're looking to automate patching at scale and get weeks, even months of your time back, go to smashingsecurity.com/action1 and sign up for patching that just works.</v>

35
00:04:27.648 --> 00:04:37.648
<v Graham Cluley>That's right. It's not a disguise-free trial. There's no credit card required.</v>

36
00:04:37.648 --> 00:04:47.648
<v Graham Cluley>There's no hidden limits. All you have to do is visit smashingsecurity.com/action1 and get started today. And thanks to Action 1 for supporting the show.</v>

37
00:04:47.648 --> 00:04:57.648
<v Graham Cluley>So, Duck, I need to make an apology. Not specifically to you, to the listeners, I think. Back in February, I had a bit of a rant with James Ball about the smart glasses made by Meta, and I explained how Mark Zuckerberg's company was planning to turn on facial recognition within the glasses and how it had been reported that there was this secret internal memo inside the company that said—</v>

38
00:05:12.173 --> 00:05:17.211
<v Paul Ducklin>I thought you were going to say inside the glasses, which would be more exciting.</v>

39
00:05:17.211 --> 00:05:24.595
<v Graham Cluley>No memo inside the glasses.</v>

40
00:05:24.595 --> 00:05:31.976
<v Graham Cluley>They had this secret memo where they said, "Look, there's going to be a bit of aggro when we launch this.</v>

41
00:05:31.976 --> 00:05:39.360
<v Graham Cluley>You know, people who care about privacy and stuff are going to object." And so they said, "The best thing that we can do is time this to be when there's some other political chaotic event going on, distracting all those civil liberties people."</v>

42
00:05:39.360 --> 00:05:45.528
<v Paul Ducklin>That is much, much, much more a question of deep thought and planning than, "Hey, let's just do it late on a Friday afternoon." Yes. Let's do it when World War III breaks out.</v>

43
00:05:45.528 --> 00:05:51.696
<v Paul Ducklin>No one will notice.</v>

44
00:05:51.696 --> 00:06:00.697
<v Graham Cluley>Anyway, the reason why I need to apologize about this is because I know some listeners may have been put off Meta Smart Glasses because of that.</v>

45
00:06:00.697 --> 00:06:02.065
<v Paul Ducklin>Oh dear.</v>

46
00:06:02.065 --> 00:06:15.476
<v Graham Cluley>Yeah. So I'm going to hope to address that right now by convincing everybody else listening that they also should not buy Meta Smart Glasses.</v>

47
00:06:15.476 --> 00:06:28.889
<v Graham Cluley>So there's another reason, as if that weren't bad enough, 11 episodes ago, we are back with another alarming story emerging about how these AI smart glasses that are being sold on the high street, and I was in an airport recently, it was in a duty-free store. They've been sold all around the world.</v>

48
00:06:28.889 --> 00:06:34.660
<v Paul Ducklin>Are they getting bought though? Do people really like these things?</v>

49
00:06:34.660 --> 00:06:37.545
<v Graham Cluley>Millions of them have been sold already, Duck.</v>

50
00:06:37.545 --> 00:06:37.817
<v Paul Ducklin>Really?</v>

51
00:06:37.817 --> 00:06:46.062
<v Graham Cluley>Something like 7 million or something.</v>

52
00:06:46.062 --> 00:06:54.307
<v Graham Cluley>People are going around with these Buddy Holly-style glasses, and of course, these are geeky kind of glasses, but with cameras and a microphone and an AI voice assistant tucked into the frames.</v>

53
00:06:54.307 --> 00:07:02.552
<v Graham Cluley>And if you hear what Meta are saying about them, one of the central messages they push out and they want you to remember, and this is the quote they give people, is they are "designed for privacy controlled by you."</v>

54
00:07:02.552 --> 00:07:16.874
<v Paul Ducklin>Designed for privacy. So let me get that right.</v>

55
00:07:16.874 --> 00:07:31.194
<v Paul Ducklin>These are spectacles that you wear that record the entire world around you, upload stuff to the cloud even when you forget that this is happening, and that somehow improves your privacy and everybody else's. I'm loving to hear how that works, Graham. Do tell.</v>

56
00:07:31.194 --> 00:07:39.142
<v Graham Cluley>So their message is that you are in control of your data and your content.</v>

57
00:07:39.142 --> 00:07:47.091
<v Graham Cluley>This is what they claim.</v>

58
00:07:47.091 --> 00:07:55.040
<v Graham Cluley>So two Swedish newspapers, Svenska Dagbladet and Göteborgs-Posten — apologies to anyone Swedish for the mangling I've done of your beautiful language — they were working with a freelance journalist in Kenya.</v>

59
00:07:55.040 --> 00:08:02.495
<v Paul Ducklin>Ooh, when you mention Kenya, I've got a suspicion that I know where this is going and why.</v>

60
00:08:02.495 --> 00:08:04.680
<v Graham Cluley>Well, you may well be right.</v>

61
00:08:04.680 --> 00:08:07.797
<v Paul Ducklin>Does it involve something beginning with S?</v>

62
00:08:07.797 --> 00:08:15.297
<v Graham Cluley>It does. And so let's explain what's going on.</v>

63
00:08:15.297 --> 00:08:22.797
<v Graham Cluley>So when you wear your fancy Meta glasses and you say, "Hey Meta, what is this thing that I'm looking at?" the AI helpfully responds. It tells you, right?</v>

64
00:08:22.797 --> 00:08:30.297
<v Graham Cluley>And you may well ask yourself, who actually sees that footage that you've just taken? Who analyzes it?</v>

65
00:08:30.297 --> 00:08:37.797
<v Graham Cluley>And the answer is that it's 1,000-odd people sitting in front of computer screens in Nairobi. In Kenya, there is a firm called— Duck, do you want to fill in the blank?</v>

66
00:08:41.875 --> 00:08:46.452
<v Paul Ducklin>I don't know how you say it. I presume it's Sama.</v>

67
00:08:46.452 --> 00:08:53.952
<v Graham Cluley>Yeah, I don't know if it's Sama or Sama. S-A-M-A. Which one should we go for today?</v>

68
00:08:53.952 --> 00:09:01.452
<v Graham Cluley>I don't know what it is. Sama. Let's try Sama.</v>

69
00:09:01.452 --> 00:09:08.952
<v Graham Cluley>So, they are the same Sama that Meta hired previously to moderate Facebook posts. Now, as was well documented, that earlier contract ended in lawsuits and former employees of Sama describing frankly the horror and the psychological trauma that they had to endure from being made to watch what is uploaded to the internet by Facebook users in their Facebook posts. And they were doing this 10 hours odd a day, not very much money.</v>

70
00:09:08.952 --> 00:09:16.452
<v Graham Cluley>And Sama later said that they regretted, you know, taking on that work for Facebook.</v>

71
00:09:31.264 --> 00:09:40.263
<v Paul Ducklin>Yes, who would have thought that paying people modest income to decide that videos of people getting beaten up, mutilated, beheaded, perhaps even worse, is an illustrious</v>

72
00:09:40.263 --> 00:09:49.260
<v Paul Ducklin>career to offer to people in the developing world, eh?</v>

73
00:09:49.260 --> 00:09:58.243
<v Graham Cluley>It's ghastly, isn't it? Anyway, Meta then hired Sama again, but they gave them a different job.</v>

74
00:09:58.243 --> 00:10:07.224
<v Graham Cluley>Their new job was to look at the videos coming out of their smart glasses and label up what was in them so that Meta's AI could learn the difference between a flowerpot and a traffic cone.</v>

75
00:10:07.224 --> 00:10:12.514
<v Paul Ducklin>But don't these glasses just come on willy-nilly? Most people just run them all the time.</v>

76
00:10:12.514 --> 00:10:18.452
<v Graham Cluley>I imagine that would drain the battery and so forth.</v>

77
00:10:18.452 --> 00:10:24.392
<v Graham Cluley>I think normally you have to say, "Hey, Meta," a bit like, "Hey, Google," or, "Hey, Siri." You have to ask them to do something, but maybe there's an option to have them permanently on.</v>

78
00:10:24.392 --> 00:10:30.956
<v Paul Ducklin>Do they detect whether you're actually wearing them or if they're just on the side stand or in the bathroom?</v>

79
00:10:30.956 --> 00:10:37.520
<v Paul Ducklin>And do they work if they're just lying around innocently somewhere else?</v>

80
00:10:37.520 --> 00:10:51.692
<v Graham Cluley>It appears that you can just leave them lying around somewhere and they will carry on recording. So they don't do a sort of biometric nose print to know that they are balanced upon your nozzle. Nothing that.</v>

81
00:10:51.692 --> 00:10:58.826
<v Paul Ducklin>You'd think that would be pretty trivial.</v>

82
00:10:58.826 --> 00:11:05.962
<v Paul Ducklin>So you got them recording, you take them off, you put them down somewhere in a coffee shop, and then you wander off to the toilet or to the counter or whatever, they just carry on recording surreptitiously while they're on the table?</v>

83
00:11:05.962 --> 00:11:09.105
<v Graham Cluley>They carry on recording. Oh, great.</v>

84
00:11:09.105 --> 00:11:13.035
<v Paul Ducklin>Well, that definitely improves your privacy, Graham.</v>

85
00:11:13.035 --> 00:11:20.535
<v Graham Cluley>Well, okay. So these employees, as I said, they're drawing little boxes around things to say, this is a flowerpot, this is a traffic cone, this is a coffee tender, whatever it may be.</v>

86
00:11:20.535 --> 00:11:28.035
<v Graham Cluley>And, you know, but this is the reality. Duck, this is the reality.</v>

87
00:11:28.035 --> 00:11:35.535
<v Graham Cluley>This trillion-dollar industry of AI. The actual truth is there's this unglamorous manual labor which is critical to the foundations of it.</v>

88
00:11:35.535 --> 00:11:43.035
<v Graham Cluley>You know, there's an awful lot of people who are having to do this to train the AI, if AI even exists at all, to do these things.</v>

89
00:11:47.648 --> 00:11:54.634
<v Paul Ducklin>Yes. The last time I was on this podcast, we talked about— was it Your AI Slot Balls Stop Me? Where it was fake AI that actually was done by humans in the background. But it pretended to be AI and its behavior was surprisingly AI. So maybe that website had more going for it than you might think.</v>

90
00:11:54.634 --> 00:11:58.883
<v Graham Cluley>It was actually quite a fun game, wasn't it? It was quite addictive pretending to be an AI.</v>

91
00:11:58.883 --> 00:12:15.407
<v Paul Ducklin>But it does raise certain questions, doesn't it?</v>

92
00:12:15.407 --> 00:12:25.407
<v Graham Cluley>Yes, it does seem that we come across this problem all the time. It's actually humans behind these things. So the reporters interviewed more than 30 Sama workers in secret.</v>

93
00:12:25.407 --> 00:12:35.407
<v Graham Cluley>Because these people had signed NDAs, they were terrified of losing their jobs. And what it turned out was that they weren't labelling flowerpots and chihuahuas. As one of them said, they said, "We see everything from living rooms to naked bodies.</v>

94
00:12:35.407 --> 00:12:45.407
<v Graham Cluley>We see everything." And what does everything mean? It means everything. So they said, "We see footage of people on the loo." Footage of people undressing, footage of people's bank cards, footage of people watching pornography while wearing the glasses.</v>

95
00:12:57.717 --> 00:13:08.373
<v Paul Ducklin>I'd thought of all of that stuff about catching you without your underpants on. But what I hadn't thought of, which is really obvious when you think about it, is when you get out your credit card to pay for something online.</v>

96
00:13:08.373 --> 00:13:19.028
<v Paul Ducklin>Yes, you will unavoidably look straight at it. And modern credit cards have the numbers writ large so you can't get them wrong.</v>

97
00:13:19.028 --> 00:13:29.028
<v Graham Cluley>Or if you've got your glasses on, if they're recording, obviously, and you go into your password manager and some website is saying, no, you have to type in your password, you can't cut and paste it.</v>

98
00:13:19.028 --> 00:13:26.528
<v Paul Ducklin>Or if you've got one of those things that says, check that your passport has at least 6 months before it expires and you get it out and open up.</v>

99
00:13:26.528 --> 00:13:34.028
<v Paul Ducklin>Yes, it does.</v>

100
00:13:29.028 --> 00:13:39.028
<v Graham Cluley>And you say, well, show me what the password is then.</v>

101
00:13:34.028 --> 00:13:41.528
<v Paul Ducklin>And close it.</v>

102
00:13:39.028 --> 00:13:49.028
<v Graham Cluley>Then that password is being beamed through as well, isn't it? Absolutely.</v>

103
00:13:41.528 --> 00:13:49.028
<v Paul Ducklin>You've just given away all the data that somebody would need to read out the NFC chip.</v>

104
00:13:51.769 --> 00:13:58.916
<v Graham Cluley>So, as we were just discussing, one Sama worker, he described a video he saw where a man had taken his glasses off, put them on the bedside table, walked out the room. Shortly afterwards, his wife walked in, started getting changed, and the glasses were still recording.</v>

105
00:13:58.916 --> 00:14:06.062
<v Graham Cluley>She had no idea. But it's not just the video footage.</v>

106
00:14:06.062 --> 00:14:13.208
<v Graham Cluley>There's also transcripts of what is being said by people wearing the glasses.</v>

107
00:14:13.208 --> 00:14:15.543
<v Paul Ducklin>That's good for your privacy, isn't it?</v>

108
00:14:15.543 --> 00:14:21.504
<v Graham Cluley>Another great thing for your privacy. Thank you, Mark Zuckerberg.</v>

109
00:14:21.504 --> 00:14:27.464
<v Graham Cluley>Workers reviewing these conversations, they said they heard chats about crimes and all kinds of what was ominously described as dark things.</v>

110
00:14:27.464 --> 00:14:34.626
<v Paul Ducklin>You'd also basically hear people unknowingly violating things like NDAs, right?</v>

111
00:14:34.626 --> 00:14:41.791
<v Paul Ducklin>By, say, discussing work, thinking, oh well, I won't tell this to anyone else.</v>

112
00:14:41.791 --> 00:14:48.953
<v Paul Ducklin>Meanwhile, it's going into the cloud so that some system can record what they said, and someone in Kenya gets to listen to it in case it got the words wrong.</v>

113
00:14:48.953 --> 00:14:55.428
<v Graham Cluley>Wow. So, this isn't good. I don't— You know what, Graham?</v>

114
00:14:55.428 --> 00:14:59.274
<v Paul Ducklin>I reckon I might not buy these things. I might just skip it.</v>

115
00:14:59.274 --> 00:15:03.378
<v Graham Cluley>Okay, I've convinced one person. All right, let's work on the rest of you now, you listeners.</v>

116
00:15:03.378 --> 00:15:07.288
<v Paul Ducklin>Thanks for the warning.</v>

117
00:15:07.288 --> 00:15:14.788
<v Graham Cluley>So, Meta told the BBC that footage stays on your device unless you choose to share it with the AI. So they say there's clear user consent, they say. They say faces are blurred.</v>

118
00:15:14.788 --> 00:15:22.288
<v Graham Cluley>It's all very above board, says Meta. So the reporters looked at that one by one to see if that was true, and they found that the blurring fails. According to workers at Sama and former employees at Meta, faces which are meant to be obscured aren't, particularly in low light, like for instance, a bedroom, or when the camera's moving quickly, which of course, if you have glasses on your face and you turn your head, your camera is moving quickly.</v>

119
00:15:22.288 --> 00:15:29.788
<v Graham Cluley>So the blurring is not reliable. Also, Meta says that it's only when you choose to share your data. So these reporters in Sweden, they bought a pair of glasses themselves and they went through the setup and the app asked, would you like to share extra data with Meta to help improve the products?</v>

120
00:15:29.788 --> 00:15:37.288
<v Graham Cluley>And they said no. Oh, extra data. Yes, I wondered if that extra data was carrying quite a lot.</v>

121
00:16:14.403 --> 00:16:22.557
<v Paul Ducklin>It's like cookies. Do you want no cookies? Okay, then we'll only use the ones we really think are important.</v>

122
00:16:22.557 --> 00:16:36.144
<v Graham Cluley>So they tried to use the glasses offline. The AI part of the glasses offline wouldn't work, wouldn't even start.</v>

123
00:16:36.144 --> 00:16:49.730
<v Graham Cluley>The AI required a constant connection to Meta's servers. So you can opt out of sharing data all that you like, but every single time you try and use that sort of, hey Meta feature, your audio and video are being beamed off to a data centre and may well end up in Nairobi being analysed by a person.</v>

124
00:16:49.730 --> 00:16:55.870
<v Paul Ducklin>Yes, because there's absolutely no way you could get enough computing power into a pair of spectacles</v>

125
00:16:55.870 --> 00:17:02.009
<v Paul Ducklin>to do cloud-level environment-ruining AI comprehension.</v>

126
00:17:02.009 --> 00:17:09.509
<v Graham Cluley>Yeah, these things aren't good. These things aren't good. Oh, and finally, the journalist went round to about 10 opticians in Stockholm and Gothenburg who actually sell the glasses, and they asked them, how is the data handled? And one said, nothing shared with Meta.</v>

127
00:17:09.509 --> 00:17:17.009
<v Graham Cluley>That was a big concern for me as well, but you have full control. Not true. Another said, everything stays locally in the app. Not true.</v>

128
00:17:17.009 --> 00:17:24.509
<v Graham Cluley>So these are the people selling the product in high street shops in countries that take privacy fairly seriously. This has become big news and you'd think Meta might apologise 'cause the ICO and others, they're all sharpening their knives over this. And what Meta actually did last week was they sacked everybody. They terminated the contract with Sama.</v>

129
00:17:24.509 --> 00:17:32.009
<v Graham Cluley>1,108 employees in Nairobi have been fired. The very people who blew the whistle have been kicked out the door. So—</v>

130
00:17:58.917 --> 00:18:02.192
<v Paul Ducklin>Is that under guise of breaking their NDA or something?</v>

131
00:18:02.192 --> 00:18:03.636
<v Graham Cluley>Well, who knows?</v>

132
00:18:03.636 --> 00:18:11.503
<v Paul Ducklin>Or is it just one of those things they go, oh, sorry, the contract's over. So we haven't exactly sacked you. It's just that your job became redundant.</v>

133
00:18:11.503 --> 00:18:17.332
<v Graham Cluley>Yeah, I think so. So Meta says that Sama did not meet their standards.</v>

134
00:18:17.332 --> 00:18:23.160
<v Graham Cluley>So they've gone to someone else, presumably. It seems the real reason is that the workers spoke to journalists.</v>

135
00:18:23.160 --> 00:18:25.327
<v Paul Ducklin>They didn't meet their standards. Oh, you mean, so if they just kept stum. Yeah. And this whole thing about facial blurring, it just occurred to me, Graham, that that is a little bit of a red herring if you think about it. Because if your video has ever caught you, say, looking at your passport or looking at your password manager or looking at your credit card, who you are is pretty obvious. And then if there's anything that looks like a household background, it's pretty obvious who the faces in the picture are most likely to be. So blurring them doesn't really help. It could easily be pieced together.</v>

136
00:18:25.327 --> 00:18:32.827
<v Graham Cluley>So if you've been using these glasses and used their AI features, if you've looked at a bank statement, if you looked into the mirror, if you've done something a bit romantic while wearing them, there is a non-zero chance that footage has been seen on a screen by a human.</v>

137
00:18:32.827 --> 00:18:40.327
<v Graham Cluley>And there's nothing you can do about that now.</v>

138
00:18:40.327 --> 00:18:47.827
<v Graham Cluley>You can stop using the AI features going forward, but that's about it.</v>

139
00:18:47.827 --> 00:18:55.327
<v Graham Cluley>But worse still, and I'm sure this is the sort of thing that upsets you as well as me, Doug, is that if you see somebody else wearing them, someone you didn't agree to be filmed by, you're probably right to be paranoid that maybe your picture or what you're doing is being uploaded there as well.</v>

140
00:19:43.023 --> 00:19:50.523
<v Paul Ducklin>And although in a public place, certainly in the UK, you don't have much, you have some, but not much expectation of privacy.</v>

141
00:19:50.523 --> 00:19:58.023
<v Paul Ducklin>People are allowed to film in public places if they want to take photos.</v>

142
00:19:58.023 --> 00:20:05.523
<v Paul Ducklin>This is a little bit different where somebody is recording their point of view and the things that are going on in their vicinity essentially continuously, and then possibly even without realizing it themselves, are kind of sharing that information with someone else.</v>

143
00:20:05.523 --> 00:20:13.023
<v Paul Ducklin>It's not even enough to trust the person who's wearing the glasses and go, well, they're a good friend, they wouldn't do me down, 'cause they might be doing you down without even knowing.</v>

144
00:20:24.714 --> 00:20:31.325
<v Graham Cluley>Horrible. So, I hope this apology has been acceptable, because I know there were some of you who hadn't been put off buying Meta glasses.</v>

145
00:20:31.325 --> 00:20:37.934
<v Graham Cluley>Hopefully now all of you are. And now a word from our sponsor.</v>

146
00:20:37.934 --> 00:20:42.932
<v Paul Ducklin>Let me guess which company it's not.</v>

147
00:20:42.932 --> 00:20:50.432
<v Graham Cluley>We've just got a moment to thank one of this episode's sponsors, ESET. Now, there's no shortage of cybersecurity vendors claiming to be the best, of course, but ESET is one of the few that's been proven it for 30 years. Research has always been at the core of what ESET does. Their threat intelligence teams are actively tracking APT groups and ransomware affiliates and publishing findings that the security community actually reads and references. That's not a marketing line.</v>

148
00:20:50.432 --> 00:20:57.932
<v Graham Cluley>That's 30 years of doing the work. And here's what makes it interesting. 3 decades of research means that ESET has built up global telemetry that most vendors simply don't have access to. They combine that telemetry with AI-native technology and human expertise, and that's what powers both their products and their MDR service. Real intelligence behind the protection, not just pattern matching.</v>

149
00:20:57.932 --> 00:21:05.432
<v Graham Cluley>110 million users worldwide trust ESET with their endpoints, cloud, email, and mobile devices. That number doesn't happen by accident. So why don't you check them out right now? Go to smashingsecurity.com/ESET. That's smashingsecurity.com/ESET.</v>

150
00:21:05.432 --> 00:21:12.932
<v Graham Cluley>And thanks to ESET for supporting the show. Duck, what have you got for us this week?</v>

151
00:22:07.938 --> 00:22:15.438
<v Paul Ducklin>Graham, I would like to talk about what I call a brain bug with an impressive name. Listeners will probably remember things like Heartbleed and Lucky 13 and Poodle and amazing bug names that stick in the mind because somebody decided, hey, I'm so proud of myself for finding this bug and disclosing it that I don't just want to be a name in someone's bug report 3 months later. I want a website, a special domain, a logo.</v>

152
00:22:15.438 --> 00:22:22.938
<v Paul Ducklin>And even in one famous case, there's a theme tune. And so some bugs maybe get a notoriety or a degree of coverage that's perhaps bigger than they really deserve. Not that it's bad to know about bugs.</v>

153
00:22:22.938 --> 00:22:30.438
<v Paul Ducklin>The problem is that if you're focusing on something which is important but not critical, what are you losing sight of? Because there's one that's caught the media's attention. And the one I want to talk about right now is called Copy Fail.</v>

154
00:22:30.438 --> 00:22:37.938
<v Paul Ducklin>And it is all over the IT media and it's getting posted and reposted and copy-pasted all over social networks, I guess, because clicks.</v>

155
00:23:30.691 --> 00:23:36.625
<v Graham Cluley>So Copy Fail, how did it get the name, first of all? Because that obviously is the most important thing of all.</v>

156
00:23:36.625 --> 00:23:47.539
<v Paul Ducklin>Well, the name is not entirely unreasonable. It is a feature in the Linux kernel that aims to speed up some particular process by</v>

157
00:23:47.539 --> 00:23:58.454
<v Paul Ducklin>actually avoiding copying memory in and out between the kernel and a program and back from the program to the kernel to save time.</v>

158
00:23:58.454 --> 00:24:01.183
<v Graham Cluley>Oh, so it's nothing to do with the clipboard, for instance?</v>

159
00:24:01.183 --> 00:24:08.683
<v Paul Ducklin>No, it isn't. So it's not— don't confuse it with ClickFix, which does include the clipboard. So the copy is just a generic term for copying memory. And in fact, the whole reason for this bug is trying to avoid copying things between blocks of memory as much as possible. And fail just means it didn't work.</v>

160
00:24:08.683 --> 00:24:16.183
<v Paul Ducklin>So that's the researchers' justification for choosing the name. My suspicion is that the nice thing about that name rather than any other is that firstly, there is a top-level domain,.fail. Is there? And yes. And the domain name copy was not taken.</v>

161
00:24:16.183 --> 00:24:23.683
<v Paul Ducklin>And as you say, copy, people might think, hey, there's a clipboard involved, all of that stuff. So I suspect that they chose the name because it's not unreasonable, but they were able to get the domain. So I think it's a bit like, you know how US lawmakers love to give their laws fancy names that you can remember. And you think, hey, what's the chance of that? So, you know, they have a law and say, oh, this is the Fandango Act.</v>

162
00:24:23.683 --> 00:24:31.183
<v Paul Ducklin>And then you think, Fandango, what on earth is that? And then when you hear it, it's some weird concoction like, I don't know, I'm trying to make one up as I go along, Federal Arrangement Never to Disparage Aerospace Navigation by Geographic Obstinacy or something. And you think—</v>

163
00:25:29.411 --> 00:25:31.751
<v Graham Cluley>Round of applause, round of applause for that.</v>

164
00:25:31.751 --> 00:25:39.251
<v Paul Ducklin>TikTok. Well done.</v>

165
00:25:39.251 --> 00:25:46.751
<v Paul Ducklin>I may have missed some letters out. And you think, okay, I get the idea.</v>

166
00:25:46.751 --> 00:25:54.251
<v Paul Ducklin>So I think in this case, they maybe figured, hey, we can get the domain name, we can get the website, we can promote this because for better or for worse, the reason they want to talk up this particular bug, Copyfail, is that the principle of the bug was uncovered by a human researcher who then used this company's AI bug hunting tool to go looking for code examples in the kernel where this very kind of bug might have happened. Okay.</v>

167
00:25:54.251 --> 00:26:01.751
<v Paul Ducklin>And they found several, and this was the worst of them. So clearly, if not their primary goal, at least their major secondary goal is to talk up their bug hunting statistical analysis tool.</v>

168
00:26:24.722 --> 00:26:31.609
<v Graham Cluley>Fair enough. It does strike me that AI is at the very heart of every fail, isn't it?</v>

169
00:26:31.609 --> 00:26:38.498
<v Graham Cluley>It is at the centre of the word fail. So, I mean, it's— so they found this bug, right?</v>

170
00:26:38.498 --> 00:26:45.384
<v Graham Cluley>And without getting into the really nerdy detail of how it works, what does it do? What is it?</v>

171
00:26:45.384 --> 00:26:52.884
<v Paul Ducklin>That's a great question because it gets to the heart of is this really as big a story as you might imagine if you just scroll through LinkedIn and when you see people posting, of all the cybersecurity bugs you're going to get, this is the new disaster area. So as you've mentioned before on the podcast, Graham, there's a thing called CVSS, which I think is Common Vulnerability Scoring System, which is a kind of mark out of 10 for how bad the bug is. So Log4Shell, remember that about 5 years ago? That was a 10.0 critical. Like, deal with it now because somebody could go to your website, put in their name into a form on the webpage, then add some weird characters and bingo, they just told your web server, hey, go and download this Java program and run it.</v>

172
00:26:52.884 --> 00:27:00.384
<v Paul Ducklin>Game over. So that's pretty obviously a clear and present danger. Remember WannaCry, the EternalBlue vulnerability stolen from the NSA in the US? Well, it had been patched for a couple of months beforehand. Lots of people didn't patch.</v>

173
00:27:00.384 --> 00:27:07.884
<v Paul Ducklin>That virus went everywhere, spread automatically, wiped people's hard disks, That only got an 8.8 high. And this bug is at 7.8 high. So you could think, why is this considered such a big catastrophe if not merely for the fact that it's a bit of a marketing vehicle, maybe slightly dubiously, you might say, for the company that found and reported it? So as bugs go, the worst bugs are normally the ones that are called RCE, remote code execution, like the Log4Shell one. It means someone on the other side of the world can do something to your computer, typically by sending it a network packet or typing something in on your website, and bingo, they implant malware on your computer just like that.</v>

174
00:27:07.884 --> 00:27:15.384
<v Paul Ducklin>They execute a program without permission remotely. Clearly, that's super dangerous, but this is not one of those. It's not at that level that somebody can take over your web server or your cloud backup service or the webmail service you provide to your customers or your financial system or your online store. It's not like they can use this bug to go in and just break in in the first place.</v>

175
00:27:59.430 --> 00:28:09.430
<v Graham Cluley>And this bug is in Linux</v>

176
00:28:09.430 --> 00:28:19.430
<v Graham Cluley>boxes, isn't it? It's not going</v>

177
00:28:19.430 --> 00:28:29.430
<v Graham Cluley>to impact people who have got Windows.</v>

178
00:29:14.361 --> 00:29:21.861
<v Paul Ducklin>I think you need to be a little bit careful about saying that. Because more of the world runs on Linux, you might say, than runs on Windows these days. So although it doesn't affect your laptop, it might affect the systems that your laptop connects to. Which include AI servers, backup services, webmail hosts, all of that stuff, which mostly do, not all, but very many do run on Linux.</v>

179
00:29:21.861 --> 00:29:29.361
<v Paul Ducklin>So the good news is that this is not a 10.0 critical game over. So it probably shouldn't have got quite the coverage that it did. It is what's known as an EOP or elevation of privilege. In other words, it's the kind of bug that if someone gets in, but they only managed to break in as Graham Cluley or guest, they can then use this second bug to basically boost their access and get admin level, or in Linux terms, root power.</v>

180
00:29:29.361 --> 00:29:36.861
<v Paul Ducklin>So that is bad because, as we know, particularly ransomware crooks love to chain exploits together. They break in and you can ransomware someone's computer or servers without having root access because usually you, the user, have access to all your files and that's all you care about. However, it's much more devastating if they can get admin-level access first. So you do often get remote code execution bugs chained with EOPs, elevation of privilege.</v>

181
00:29:36.861 --> 00:29:44.361
<v Paul Ducklin>So I don't want to underplay this bug, but it doesn't mean that someone can break into your computer. And as you say, because it's Linux-specific, it relies on you running the Linux kernel. It's not directly going to affect anybody who's got a Mac or who is running Windows.</v>

182
00:31:06.618 --> 00:31:16.308
<v Graham Cluley>So if I'm a sysadmin listening to this, is there anything that I should be doing about this, or is there anything which I shouldn't be doing?</v>

183
00:31:16.308 --> 00:31:26.000
<v Graham Cluley>Even if you're saying it's not the end of the world as we know it, there'll be many people who will think, well, I still don't want this problem residing on my systems.</v>

184
00:31:26.000 --> 00:31:33.500
<v Paul Ducklin>No, particularly if you run a Linux server where you provide multiple users with access. So maybe someone's got a server and they say, "Hey, Graham, would you like a login on it?" You go, "Yeah, that would be very handy.</v>

185
00:31:33.500 --> 00:31:41.000
<v Paul Ducklin>I might run a web server." And they said to Duck, "Would you like a login?" And I said, "Oh yes, I'd love to use it for my backups." Now, what if either of us could promote ourselves to root access and therefore read each other's files? That would not be good.</v>

186
00:31:41.000 --> 00:31:48.500
<v Paul Ducklin>So you definitely want to stop this. Now, this bug has been patched.</v>

187
00:31:48.500 --> 00:31:56.000
<v Paul Ducklin>So it's a great reminder to everybody who runs Linux systems: patch early, patch often. The new fixed kernel that no longer has this buffer leak is immune to this particular exploit.</v>

188
00:32:18.355 --> 00:32:24.682
<v Graham Cluley>Well, we've got time right now to chat about one of our sponsors this week, Vanta.</v>

189
00:32:24.682 --> 00:32:26.207
<v Joe>Oh yes, my favourite.</v>

190
00:32:26.207 --> 00:32:31.021
<v Graham Cluley>What do they do again? They stop you running your entire security program out of a spreadsheet, Joe.</v>

191
00:32:31.021 --> 00:32:32.788
<v Joe>That seems aimed at me personally, Graham.</v>

192
00:32:32.788 --> 00:32:40.829
<v Graham Cluley>Well, it is a little bit, yes.</v>

193
00:32:40.829 --> 00:32:48.871
<v Graham Cluley>But you know how most companies have to prove they're secure to customers or auditors and regulators, and the whole thing involves chasing down evidence, filling in questionnaires and forms, updating the same spreadsheet cells over and over again.</v>

194
00:32:48.871 --> 00:32:50.765
<v Joe>It sounds utterly soul-destroying.</v>

195
00:32:50.765 --> 00:32:57.777
<v Graham Cluley>Yeah. Well, Vanta automates all of that.</v>

196
00:32:57.777 --> 00:33:04.789
<v Graham Cluley>Automates it, how? Well, their trust management platform keeps a continuous eye on your systems.</v>

197
00:33:04.789 --> 00:33:11.801
<v Graham Cluley>It pulls everything into one place and keeps you audit ready around the clock. So no more staring at the ceiling at 2 AM wondering whether you've got the right controls in place or whether one of your suppliers has been breached.</v>

198
00:33:11.801 --> 00:33:13.391
<v Joe>The stuff of nightmares.</v>

199
00:33:13.391 --> 00:33:20.586
<v Graham Cluley>Yeah, it would be, wouldn't it?</v>

200
00:33:20.586 --> 00:33:27.781
<v Graham Cluley>But this Vanta solution uses AI as well, and it's the useful kind, flagging risks, collecting evidence, slotting into the tools your team already uses so you move faster, scale without the headaches, and perhaps actually get some sleep.</v>

201
00:33:27.781 --> 00:33:34.977
<v Graham Cluley>Go to vanta.com/smashing to find out more.</v>

202
00:33:34.977 --> 00:33:42.634
<v Joe>That's vanta.com/smashing. And thanks to Vanta for supporting the show.</v>

203
00:33:42.634 --> 00:33:46.515
<v Graham Cluley>And welcome back. Can you join us for our favourite part of the show? The part of the show that we like to call Pick of the Week.</v>

204
00:33:46.515 --> 00:34:16.514
<v Paul Ducklin>Pick of the Week.</v>

205
00:33:46.515 --> 00:33:51.161
<v Graham Cluley>Pick of the Week is the part of the show where everyone chooses something they like. Could be a funny story, a book that they've read, a TV show, a movie, a record, a podcast, a website, or an app, whatever they wish. It doesn't have to be security related necessarily. Well, my pick of the week this week is not security related. My pick of the week this week is a radio program which I heard, a lovely little radio documentary. You can go and find it on BBC Sounds, and it's just 20 minutes long, and it's about a man called Arthur Haley who came from Luton in Bedfordshire. And do you know what Arthur Haley's claim to fame is?</v>

206
00:33:51.161 --> 00:33:53.496
<v Paul Ducklin>Is this a fictional story, or is it actually a sort of documentary thing?</v>

207
00:33:53.496 --> 00:34:08.496
<v Graham Cluley>This is a true</v>

208
00:34:08.496 --> 00:34:23.496
<v Graham Cluley>story. Really? Yes.</v>

209
00:34:33.916 --> 00:34:39.146
<v Paul Ducklin>I know about Bill Haley and the Comets. But I don't know about Arthur Haley.</v>

210
00:34:39.146 --> 00:34:46.646
<v Graham Cluley>Well, it does hail from the sky. Oh, well done, Graham.</v>

211
00:34:46.646 --> 00:34:54.146
<v Graham Cluley>That's the same time as Bill Haley and the Comets were rocking around the clock. Because Arthur Hailey, he was on an aeroplane back in the 1950s, and he was on this plane, and he wondered to himself on this rather long journey, because he lived in Canada at the time, although he'd been born in Luton, and he wondered, "I wonder what would happen if the pilots became ill?</v>

212
00:34:54.146 --> 00:35:01.646
<v Graham Cluley>Would I be able to land this plane?" he thought to himself. So, this got him thinking, and so he wrote a little play.</v>

213
00:35:01.646 --> 00:35:09.146
<v Graham Cluley>And in 1956, it was shown on CBC, which is the Canadian Broadcasting Channel, a TV drama called Flight Into Danger about exactly that, about what happens when there's a plane and the pilots become sick from food poisoning or whatever, and one of the passengers has to land the plane, guided down by someone on the ground in air traffic control.</v>

214
00:35:40.057 --> 00:35:45.115
<v Paul Ducklin>I've seen a film that, but it was not a documentary, Graham.</v>

215
00:35:45.115 --> 00:35:52.081
<v Graham Cluley>No, what you are thinking is the hit comedy movie Airplane!, of course, with Leslie Nielsen, as well as other films over the years. What's your vector, Victor? That one.</v>

216
00:35:52.081 --> 00:35:59.045
<v Graham Cluley>What was it? "Surely, you're joking," or something. Anyway, but yes.</v>

217
00:35:59.045 --> 00:36:01.884
<v Paul Ducklin>Yes, "Don't call me Shirley." All of that, yes.</v>

218
00:36:01.884 --> 00:36:09.384
<v Graham Cluley>So Arthur Hailey wrote this as a straight play. Yes, I'm thinking it sounds the kind of thing that would be quite thoughtful. Apparently, it was an absolute sensation on Canadian television. They didn't have to have very many sets.</v>

219
00:36:09.384 --> 00:36:16.884
<v Graham Cluley>It could be done cheaply. And at the time, these were all broadcast live, right? They would just act in front of the cameras, and all you needed was a set of the man down in air traffic control and over on the other side of the studio, the cockpit. And apparently, people went crazy for this.</v>

220
00:36:16.884 --> 00:36:24.384
<v Graham Cluley>And the BBC, they decided to do their own version, and then they got hold of the Canadian version. They said, "You know what? This Canadian version is so good. We're going to show the Canadian version instead on BBC." And again, it was a sensation.</v>

221
00:36:24.384 --> 00:36:31.884
<v Graham Cluley>People have said they'd never seen anything like it. What I listened to was a documentary all about Flight Into Danger. And even though I've never seen it, I was absolutely fascinated. A lovely little documentary.</v>

222
00:36:58.306 --> 00:37:06.608
<v Paul Ducklin>So this is the real story behind the— Yes. I think the word fatuous applies perfectly well to the film Airplane!</v>

223
00:37:06.608 --> 00:37:14.108
<v Graham Cluley>They interviewed people who played, for instance, the air stewardess. Wow, she's now 93 years old, and they were interviewing her as well as to her memories of all of this. Lovely documentary. It also helped the career of people Sidney Newman, who came to the British Isles and launched TV shows The Avengers and Doctor Who after the success of this Canadian programme as well.</v>

224
00:37:14.108 --> 00:37:21.608
<v Graham Cluley>I'd recommend it. Go and check it out. I'll put links in the show notes. Lovely 20-minute-long documentary.</v>

225
00:37:21.608 --> 00:37:29.108
<v Graham Cluley>I just thought, this is really great, and I wanted to share it with people. So, there you are. That was the origin of the movie Airplane!, and it sounds it's really good. Maybe someone recorded it.</v>

226
00:37:29.108 --> 00:37:36.608
<v Graham Cluley>Maybe there is a version online which I can go and check out.</v>

227
00:37:46.686 --> 00:37:55.507
<v Paul Ducklin>That would be good, wouldn't it? Although an awful lot of old film and video footage has been lost. It has, yes.</v>

228
00:37:55.507 --> 00:38:04.329
<v Paul Ducklin>I know the BBC used to just reuse the videotapes because they were so expensive. Just record over a programme they'd made, no matter what a hit it had been.</v>

229
00:38:04.329 --> 00:38:11.188
<v Graham Cluley>It's an absolute cultural tragedy that so much has been destroyed. And that's why I love things the Internet Archive, which has been preserving old websites, keeping all this stuff because it is our culture.</v>

230
00:38:11.188 --> 00:38:18.045
<v Graham Cluley>You know, we don't want that to have all been erased as well.</v>

231
00:38:18.045 --> 00:38:25.545
<v Paul Ducklin>Well, did you see lately there's an appeal from some European broadcasting union asking people to look around and see if they have any recordings in any condition whatsoever of various early Eurovision song contests?</v>

232
00:38:25.545 --> 00:38:33.045
<v Paul Ducklin>Because apparently several years are just missing.</v>

233
00:38:33.045 --> 00:38:40.545
<v Paul Ducklin>And they desperately try and reconstruct the history of Eurovision from the very first one.</v>

234
00:38:40.545 --> 00:38:48.045
<v Paul Ducklin>They're probably in an attic somewhere, but how would you ever know?</v>

235
00:38:50.226 --> 00:38:56.862
<v Graham Cluley>It'd be some masochist who's kept a copy of them. Duck, what's your pick of the week?</v>

236
00:38:56.862 --> 00:39:05.960
<v Paul Ducklin>My pick of the week, well, I had a pick of the week. I've suddenly got an extra one, if that's okay. So when you started talking about the Meta Glasses fiasco, the reason I knew about Sama, was because of an excellent book that I read quite some time ago that my wife bought for me, which is called Code Dependent, with the subtitle How AI is Changing Our Lives, by a British journalist who's originally from India called Madhumita Murgia. I think she's a journalist with the FT. And she actually went to Nairobi and met with several of the people who worked on various parts of Sama, people who'd seen the terrible stuff people who'd sat there for hours looking for traffic cones and everyone in between. And that's just one of the many chapters that she digs into. It's a very well-recommended book. But the one that I actually declared in advance to you that I was going to mention, I will now mention. I just happened to reread this. It's a book that came out towards the end of last century, so it's very slightly dated by now. But it's interesting to see how much of it has not dated. And it is a book called The Code Book, subtitled The Secret History of Codes and Codebreaking, by a well-known British science popularizer journalist called Simon Singh.</v>

237
00:39:05.960 --> 00:39:15.057
<v Paul Ducklin>And it's an excellent review of some key stuff in cryptography, the strengths and the weaknesses. It's entirely coincidental that I was reading this book when the whole copy fail thing came out, and it turned out that ironically, a bug in some cryptographic code that was supposed to make the world a safer place ended up potentially opening up your computer to anybody who could log in as root. That was a coincidence. But the book is full of reminders. In fact, there's even a chapter called Le Chiffre Indéchiffrable, the Undecipherable Cipher, which is a cipher called the Vigenère cipher, which was thought to be unbeatable because it was just so clever. And eventually, actually, Charles Babbage, I think, was the first person who came up with a way to defeat it. But he's not remembered for that because he came up with his way to solve it very reliably, even though the cipher's quite hard to crack. He came up with a trick for breaking into it, and he discovered this just before the Crimean War with Russia back in the mid-19th century. So the theory is that he was told to keep quiet about it, and he never got any credit for cracking it. The credit went to someone else several years later, and his cracking it was kept quiet because I suppose the British were afraid that the Russians might stop using it if they knew that it had been cracked. So it's a fascinating book full of those stories about how what seems impenetrable at first sight can either be cracked by a bit of cleverness or sidestepped completely by a bit of manipulation, bribery, corruption, social engineering, or what have you. Well, I can recommend the book as well.</v>

238
00:39:15.057 --> 00:39:25.057
<v Graham Cluley>I read it many years ago, and I</v>

239
00:39:25.057 --> 00:39:35.057
<v Graham Cluley>also read another book of Simon Singh's, Fermat's</v>

240
00:39:35.057 --> 00:39:45.057
<v Graham Cluley>Last Theorem, as well. An interesting story.</v>

241
00:42:31.148 --> 00:42:44.333
<v Paul Ducklin>That's particularly interesting if you live in Oxford, because not too far from me is the Sir Andrew Wiles Mathematical Building. And Sir Andrew Wiles got his knighthood because he's the guy who finally, after centuries, proved Fermat's theorem in hundreds of pages.</v>

242
00:42:44.333 --> 00:42:57.518
<v Paul Ducklin>He made it his life's work from apparently when he was a kid, and he just focused on that. And he got there in the end.</v>

243
00:42:57.518 --> 00:43:03.568
<v Graham Cluley>Terrific. Well, great picks of the week. Right, well, we've got a bit of time now to have a featured interview.</v>

244
00:43:03.568 --> 00:43:09.617
<v Graham Cluley>We're going to chat to Jake Moore, the global security advisor at ESET. Hello, Jake. Great to have you on the show.</v>

245
00:43:09.617 --> 00:43:11.860
<v Jake Moore>Hello, Graham. Lovely to be here.</v>

246
00:43:11.860 --> 00:43:19.391
<v Graham Cluley>Well, you have been experimenting lately with this old deepfake nonsense, haven't you? Tell me about this face swap experiment which you did.</v>

247
00:43:19.391 --> 00:43:26.891
<v Jake Moore>Yeah, so I love deepfakes. I love to play with the latest tools that criminals might be using and test them for good, of course, so people can learn from it. But there are so many incredible tools out there.</v>

248
00:43:26.891 --> 00:43:34.391
<v Jake Moore>And I saw this incredible headline that said that a company had hired a North Korean cybercriminal by accident. And I was so intrigued by that. I thought, I wonder if that's actually possible.</v>

249
00:43:34.391 --> 00:43:41.891
<v Jake Moore>And so a couple of years ago, I started playing around with face swapping technology. And it wouldn't work very well. It just looked so fake.</v>

250
00:43:41.891 --> 00:43:49.391
<v Jake Moore>And so recently I've been able to do it and I thought, I wonder if I could actually fool someone for the greater good of education. And I got through a round of interviews by multiple people as someone else. And it was a lot of fun.</v>

251
00:44:09.123 --> 00:44:12.896
<v Graham Cluley>Hang on, this is interesting. Okay, so who did you target when you did this?</v>

252
00:44:12.896 --> 00:44:20.396
<v Jake Moore>So I was looking around for companies that would allow me to do this, 'cause I wanted permission from the top. And I got permission from a CEO that I know, and he said this would be a great experiment for us as well.</v>

253
00:44:20.396 --> 00:44:27.896
<v Jake Moore>You know, good to see how our hiring process is. And so I got all of the things together, CV, I even made a passport, and all the extras that might be looked into.</v>

254
00:44:27.896 --> 00:44:35.396
<v Jake Moore>And the biggest thing that I had to get around was actually the nerves. I haven't been for an interview for a long time.</v>

255
00:44:35.396 --> 00:44:42.896
<v Jake Moore>And now I was able to use the software through a virtual camera, throwing myself into this Teams interview and see two people staring at me. And so nervously looking back at them thinking, surely they're gonna spot that I'm a deepfake.</v>

256
00:44:53.887 --> 00:45:02.447
<v Graham Cluley>But it continued. So are we talking a high-end studio rig, which you're using, or is this something you could do on a gaming laptop in your bedroom?</v>

257
00:45:02.447 --> 00:45:12.447
<v Jake Moore>Yeah, you can pretty much do this on any laptop. Well, I say that you do need a fast GPU, but the quicker the computer, the more you get, say, better quality cameras.</v>

258
00:45:12.447 --> 00:45:22.447
<v Jake Moore>So in my experiment that I was testing, I found that the default camera that it came with was too good. In fact, I had to turn down the resolution and blur the background to make it look there could be some, say, audio sync issues and other problems as well.</v>

259
00:45:22.447 --> 00:45:32.447
<v Jake Moore>Also, I had this kill switch to just kill the virtual camera and throw in this green screen, say fuzziness that I'd added in the background just to give me that get out clause.</v>

260
00:45:39.748 --> 00:45:49.335
<v Graham Cluley>So weren't there any tells that a sharp-eyed interviewer might have spotted, or is it really genuinely good enough that the human eye can't catch it?</v>

261
00:45:49.335 --> 00:45:56.835
<v Jake Moore>Well, I think what we are really looking at here is just trust. People don't expect it.</v>

262
00:45:56.835 --> 00:46:04.335
<v Jake Moore>A lot of people have heard of this, but I do find it tends to be in our industry that we know this is happening. When you go to say HR, who are the people on the front line of this, they don't necessarily know about this yet, or at least at this scale, or even think it's gonna happen to them.</v>

263
00:46:04.335 --> 00:46:11.835
<v Jake Moore>And so if you throw out a good backstory, and I made up this story that I was a teacher for 14 years and I just wanted to go into the IT profession, and I'd had 2 years at a bit of IT admin, and I was starting to go into sales. The story added up, and by the time that I was chatting to them, they're probably not looking for things like, oh, the head moved slightly differently, then maybe there was an audio issue.</v>

264
00:46:11.835 --> 00:46:19.335
<v Jake Moore>This is online remote interviewing. Things can go wrong, but they overlook that because effectively they believe it.</v>

265
00:46:38.786 --> 00:46:42.059
<v Graham Cluley>So I have to ask, did they offer you the job?</v>

266
00:46:42.059 --> 00:46:49.559
<v Jake Moore>What happened? So after the first interview where I was interviewed by HR and someone in IT, I very nervously got through that interview, but then I did get a second interview. So I knew that I'd fooled them. In my mind, that was the end of the experiment, but I thought, well, I'm here now. I might as well go through it.</v>

267
00:46:42.059 --> 00:46:57.034
<v Graham Cluley>What happened when</v>

268
00:46:49.559 --> 00:46:57.059
<v Jake Moore>They gave me a task. They asked me to create a presentation. I got ChatGPT to create it beautifully, poetically. ChatGPT said, hey, if you're making a presentation for this company, do you want us to make it in their brand colors as well? I thought, yeah, what a great way of doing this.</v>

269
00:46:57.034 --> 00:47:12.010
<v Graham Cluley>you told them?</v>

270
00:46:57.059 --> 00:47:04.559
<v Jake Moore>So I made this presentation. They loved it. The next interview, it was one of the same guys and then another guy from IT. That did worry me. Now I've got two very probably clever guys looking at me that I thought they might even know about this.</v>

271
00:47:04.559 --> 00:47:12.059
<v Jake Moore>And they didn't. 45 minutes into through the call. We finish it all nicely, and a couple days later I did get an email that said congratulations. This was a £38,000 job. Wow.</v>

272
00:47:12.010 --> 00:47:19.510
<v Jake Moore>Well, I went straight to the CEO to say, you will not believe this. He was so excited to hear what happened. And I said, look, I'm gonna turn the job down. Obviously, I'm just gonna say another job's come up, but I said I don't think we should tell them. And he said, surely we have to, we need to get you in and tell everyone what's happened.</v>

273
00:47:19.510 --> 00:47:27.010
<v Jake Moore>And we, this is the educational piece that you were talking about. And I said, well, I feel so bad because what if they then feel silly? What if they feel fooled into this? Anyone could fall for this. You know, this is not a way of catching people out.</v>

274
00:47:27.010 --> 00:47:34.510
<v Jake Moore>And if you think how phishing exercises have changed, some people feel very bad about it if they've clicked on a link for whatever reason. I didn't want to use it on that level, especially as AI ironically came up in the first interview and we at length talked about AI is everywhere. And it was kind of funny, but at the same time, I don't want to put a lot of heat on those people. So I asked them if I could use the story. I do put it in a presentation.</v>

275
00:47:34.510 --> 00:47:42.010
<v Jake Moore>I blur the faces, I change the voices, and I use it as an educational piece. I've been doing it a lot with HR people as well, just so they're aware of it. But no, I just happily turned down the job and looked elsewhere.</v>

276
00:48:57.786 --> 00:49:01.489
<v Graham Cluley>You weren't tempted to carry on deepfaking yourself for the rest of your natural life?</v>

277
00:49:01.489 --> 00:49:08.989
<v Jake Moore>Funnily enough, I did go and tell my Chief Product Officer. We always chat every so often about what we're up to, and he did ask about this. And I said, you'll never guess what I've done. And he was all ears, but he's very difficult to impress.</v>

278
00:49:08.989 --> 00:49:16.489
<v Jake Moore>And so I did go and tell him the story. And at the end of it, he went, well, that's not that impressive. All you've done is you've used some software to put someone else's face, and by the way, this is an AI face, doesn't exist, on top of yours, and you used your voice, and you've just got the gift of the gab. You probably gave it a go.</v>

279
00:49:16.489 --> 00:49:23.989
<v Jake Moore>And I said, what, does that not impress you? He said, you know what, Jake, if you really wanted to impress me, why don't you do this whole interview as a woman? And then you'd have to change your hair, your voice, and your body as well to go with it. And I said, hold that thought.</v>

280
00:49:23.989 --> 00:49:31.489
<v Jake Moore>And so for the next five months, I created another new persona and I had to start the whole process again.</v>

281
00:49:55.606 --> 00:49:57.710
<v Graham Cluley>And was that successful?</v>

282
00:49:57.710 --> 00:50:05.210
<v Jake Moore>It was a lot harder because by now it was now January that I was applying for jobs. I tried everywhere, but it seems that everyone's applying for jobs in January, right?</v>

283
00:50:05.210 --> 00:50:12.710
<v Jake Moore>I was very nervous about going for these job interviews because the technology which I had tested and tested, I was always worried in a live situation, as everyone knows. You don't want to be doing live demos.</v>

284
00:50:12.710 --> 00:50:20.210
<v Jake Moore>And when you change your voice through software, you can't tell what they're hearing. So things like that would panic me.</v>

285
00:50:20.210 --> 00:50:27.710
<v Jake Moore>But I did get a few interviews as this lady, and there's lots more to go with it in this story, but I don't want to finish with telling everyone how it happens because actually I'm starting to give this talk out at a lot of conferences all over the country this year.</v>

286
00:50:38.327 --> 00:50:47.164
<v Graham Cluley>So if anyone wants to find out what happened next, go and see him on the speaking circuit. This is a serious problem, of course, because as you said at the beginning, we have seen North Korean IT workers infiltrating Western companies, and that's a real problem, isn't it?</v>

287
00:50:47.164 --> 00:50:56.000
<v Graham Cluley>I mean, what is their endgame when they're doing that?</v>

288
00:50:56.000 --> 00:51:03.500
<v Jake Moore>Yeah, so it's so creative. I do take my hat off to them. I genuinely am fascinated with crime.</v>

289
00:51:03.500 --> 00:51:11.000
<v Jake Moore>I always have been, being in the police force and now with ESET looking into what criminals are using. So I'm just so fascinated with it. It's something that was never on anyone's radar, but yet if anyone is to infiltrate a company, why not get straight into the company itself and penetrate it from within?</v>

290
00:51:11.000 --> 00:51:18.500
<v Jake Moore>If they're able to be sent a laptop, there are lots of remote jobs out there. I speak to big businesses who genuinely have this problem, who say, well, we've got contractors all around the world. We've got to send out these laptops to them and once they are on their laptop, they can do so much more than their remote attacks.</v>

291
00:51:18.500 --> 00:51:26.000
<v Jake Moore>So it is a huge worry, but on the flip side, there are these big companies saying, well, what can we do about it? We can't interview them all in the UK or wherever we might have a base because they might be anywhere in the world.</v>

292
00:51:50.900 --> 00:51:56.583
<v Graham Cluley>So what should companies be doing about it? What are the practical things they can do?</v>

293
00:51:56.583 --> 00:52:02.266
<v Graham Cluley>Or are there any practical tells which they can see if they are on a call and they think it's suspicious?</v>

294
00:52:02.266 --> 00:52:09.766
<v Jake Moore>Yeah, so there have been a few viral situations where people have, say, not wanted to cover their face with their hand. There've been some great videos like that, but it's difficult to say, come up with one simple thing like, oh, get the interviewee to cover their face with their hand or look like they're waving in front of it, because it'll only be a year or so before that can be circumnavigated. Actually, the software that I use, as soon as it sees a hand near the face, it goes back a couple of seconds and freezes to when it was just your mugshot, and it looks like you've got connection issues.</v>

295
00:52:09.766 --> 00:52:17.266
<v Jake Moore>Last year when I did that, the software would fall apart and it would show the true face. So I don't like to say that that's the way of preparing for it. So it's adding other verification methods, speaking to someone in their country as, say, like a third party to come and actually meet them.</v>

296
00:52:17.266 --> 00:52:24.766
<v Jake Moore>Meeting people in real life is still so, so vital. But I know we've got HR having their own problems because it's so busy out there. They need to cut those corners where they can.</v>

297
00:52:24.766 --> 00:52:32.266
<v Jake Moore>And unfortunately, that's where cybercriminals like to take advantage.</v>

298
00:53:07.601 --> 00:53:15.050
<v Graham Cluley>Is there more that the big video call platforms should be doing? The Zooms, the Microsoft Teams, the Google Meets, are they keeping pace?</v>

299
00:53:15.050 --> 00:53:22.550
<v Jake Moore>Yeah. So this has been a big thorn in their side for a few years. There's a company that's co-founded by Sam Altman. I mean, of course he's everywhere.</v>

300
00:53:22.550 --> 00:53:30.050
<v Jake Moore>That have just signed a deal with Zoom and Tinder to try and help verify people. I think it's far better to go down the verification route. This might be through a process of verifying through your phones of who you both are on the call. I would say that's better than actually using deepfake technology in real time, because as the technology improves, we've got this major problem where we might be able to detect something now, and then just a few months later, it'll actually come back and say, no, that's a genuine video.</v>

301
00:53:30.050 --> 00:53:37.550
<v Jake Moore>We don't see this as showing any evidence of AI. And so we really need to use more of those verification tools. There are a few others that are also trying to do it. There's nothing that I've seen for Teams at the moment, but hopefully there will be something that we can all use.</v>

302
00:53:37.550 --> 00:53:45.050
<v Jake Moore>But I think it's that testing phase at the moment. But as the technology improves, we do just see this issue probably expanding.</v>

303
00:54:14.813 --> 00:54:22.313
<v Graham Cluley>So I've just had a thought, and I'm not saying this couldn't be circumvented, but I wonder whether those video call platforms could detect the use of a virtual camera.</v>

304
00:54:22.313 --> 00:54:29.813
<v Graham Cluley>Because the way in which this works, right, is you've got a webcam in front of you looking at you.</v>

305
00:54:29.813 --> 00:54:37.313
<v Graham Cluley>You would then have a piece of software which munges that video of you to look like the deepfaked version, which is what it then sends to the video platform, right?</v>

306
00:54:37.313 --> 00:54:44.813
<v Graham Cluley>If they were able to spot that their input was actually a virtual camera rather than an actual camera— again, I know this could possibly be subverted, maybe that would cut out some of this.</v>

307
00:54:48.233 --> 00:54:58.233
<v Jake Moore>Yeah. And I was only speaking to a company only yesterday about this, and they do block virtual cameras through their own platform for that reason.</v>

308
00:54:58.233 --> 00:55:08.233
<v Jake Moore>But we ended up chatting about how that can probably be circumnavigated because it's just one of those extras. It's really difficult to say, use just this one method at the moment, because if you sing too loud about one detection or security method, everyone then says, well, that must be it.</v>

309
00:55:08.233 --> 00:55:18.233
<v Jake Moore>And before you know it, it's been bypassed, and then that's given the advantage to the criminals again.</v>

310
00:55:19.896 --> 00:55:29.523
<v Graham Cluley>So Jake, if you were a criminal, which you're not for the record, what's the next AI-enabled scam that you'd be worried about seeing in 2026? Is there a piece of security advice that's suddenly relevant again because of all of this, like meeting people in person or making a phone call to a number you already trust?</v>

311
00:55:29.523 --> 00:55:39.148
<v Graham Cluley>What is it?</v>

312
00:55:39.148 --> 00:55:46.648
<v Jake Moore>What are you afraid of? Yeah, it's sad that we are having to go back to older methods of verifying because I'm a big lover of technology as most of the listeners are going to be as well. And we all want to use AI for efficiency and speeding up our processes.</v>

313
00:55:46.648 --> 00:55:54.148
<v Jake Moore>But every time we add another tool to our wonderful technology toolkit, it can also be a way that criminals can take advantage of as well. So I really do see it's so powerful to use those extra platforms to verify who people are. A good old-fashioned phone call, meeting people in real life, never hiring someone just remotely.</v>

314
00:55:54.148 --> 00:56:01.648
<v Jake Moore>If you really can try and even get a third party, it'll cost you a lot less to hire that third party to go and meet up with whoever they are in whichever country they might be as well. But really being able to spot something, having those spider senses of just knowing that something might be up. The more people we can give that special tool to, then actually we do become safer.</v>

315
00:56:01.648 --> 00:56:09.148
<v Jake Moore>And we've got so many people that still don't know about the technology. And I think we have got a lot of the basics right, but we still haven't made a lot of people aware that the technology is rapidly moving on.</v>

316
00:56:51.786 --> 00:57:00.309
<v Graham Cluley>There's also this risk that we overcorrect, right? We end up rejecting legitimate candidates for jobs, you know, people who have unusual accents you're not familiar with, or poor lighting, or cheap webcams.</v>

317
00:57:00.309 --> 00:57:08.831
<v Graham Cluley>Because you may begin to think, oh, that, well, they could be a deepfake, therefore we're not gonna take them forward.</v>

318
00:57:08.831 --> 00:57:17.422
<v Jake Moore>Yeah, but that would be where I would start to go and meet them. Yeah, it's all okay to have the first or even second interview that.</v>

319
00:57:17.422 --> 00:57:26.012
<v Jake Moore>Ironically, in one of the interviews that I went with, the very first introductory call was actually an AI avatar that I was having to speak to.</v>

320
00:57:26.012 --> 00:57:27.135
<v Graham Cluley>Oh, for goodness sake.</v>

321
00:57:27.135 --> 00:57:30.503
<v Jake Moore>Yeah, I was AI speaking to another AI.</v>

322
00:57:30.503 --> 00:57:33.791
<v Graham Cluley>I would refuse to work for them, Jake. I would refuse.</v>

323
00:57:33.791 --> 00:57:43.768
<v Jake Moore>When it first came up, I thought, well, this is weird. What's going on? Is she real? I was, wow, they're double bluffing me.</v>

324
00:57:43.768 --> 00:57:53.744
<v Jake Moore>If anything, this is actually very impressive. They knew this was gonna be happening. But no, it was really interesting. So their whole process was, can someone sit through an introductory call where they get to learn about the company?</v>

325
00:57:53.744 --> 00:58:03.719
<v Jake Moore>At the end, I had a questionnaire to fill out and I had to answer the questions that had I been listening through the first half an hour call. I passed them 'cause I had been, and then get to go to the next interview to meet a real person.</v>

326
00:58:03.719 --> 00:58:08.864
<v Graham Cluley>So yeah, it's all change out there. It is.</v>

327
00:58:08.864 --> 00:58:14.010
<v Graham Cluley>It should be said, AI can be used for defensive purposes to improve the security of your company as well. It's not all a threat, is it?</v>

328
00:58:14.010 --> 00:58:21.510
<v Jake Moore>Yeah, AI is fantastic. It's so good at being used in, say, vulnerability finders.</v>

329
00:58:21.510 --> 00:58:29.010
<v Jake Moore>We've been using AI and machine learning in our products at ESET for many, many years. It's such a fantastic vulnerability finder in itself.</v>

330
00:58:29.010 --> 00:58:36.510
<v Jake Moore>Of course, it's going to use the latest technology. Effectively, it's firefighting fire.</v>

331
00:58:36.510 --> 00:58:44.010
<v Jake Moore>We've now got AI fighting AI. And we'll continually use that AI technology, particularly in our ESET products, to find that greater good and stop those very, say, clear attacks and even those very sophisticated ones before they go and harm those devices.</v>

332
00:58:52.643 --> 00:58:59.628
<v Graham Cluley>Well, Jake, it's been great chatting to you today and finding out all the mischief you get up to with deepfakes. I'm glad I'm not one of your colleagues being pranked by you.</v>

333
00:58:59.628 --> 00:59:06.614
<v Graham Cluley>I'd be terrified. If people want to find out more about ESET, they can go and check out your products and services at smashingsecurity.com/ESet.</v>

334
00:59:06.614 --> 00:59:13.599
<v Graham Cluley>And thanks very much, Jake, for joining us on the show.</v>

335
00:59:13.599 --> 00:59:15.849
<v Jake Moore>Well, thank you very much as well, Graham.</v>

336
00:59:15.849 --> 00:59:22.931
<v Graham Cluley>It's been great. Terrific stuff. And that just about wraps up the show for this week. Thanks to our guest, Paul Ducklin.</v>

337
00:59:22.931 --> 00:59:30.012
<v Graham Cluley>Thank you, Paul. I'm sure lots of our listeners would love to find out what you're up to and follow you online. What's the best way for them to do that?</v>

338
00:59:30.012 --> 00:59:37.230
<v Paul Ducklin>The easiest way to see who I am and what I do is to go to my website, pducklin.com, or just search for Paul Ducklin on the various social medias.</v>

339
00:59:37.230 --> 00:59:44.447
<v Paul Ducklin>So if you would like a great presenter, a great writer, a great webinar creator, a podcast editor, please get hold of me.</v>

340
00:59:44.447 --> 00:59:51.664
<v Paul Ducklin>I kind of feel I need to be on those places.</v>

341
00:59:51.664 --> 01:00:01.431
<v Graham Cluley>Ducklin without a G, I should probably point out. That's correct.</v>

342
01:00:01.431 --> 01:00:11.197
<v Graham Cluley>And of course, we're on social media as well. You can find me, Graham Cluley, on LinkedIn and all the other usual places.</v>

343
01:00:11.197 --> 01:00:20.963
<v Graham Cluley>Or follow Smashing Security on Reddit and Blue Sky on Mastodon. And don't forget to ensure you never miss another episode.</v>

344
01:00:20.963 --> 01:00:30.728
<v Graham Cluley>Follow Smashing Security in your favorite podcast apps such as Apple Podcasts, Spotify, and Pocket Casts. For episode show notes, sponsorship info, guest lists, and the entire back catalog of 466-odd episodes, check out smashingsecurity.com.</v>

345
01:00:30.728 --> 01:00:40.496
<v Graham Cluley>Until next time, cheerio, bye-bye. Bye everyone.</v>

346
01:00:40.496 --> 01:00:50.262
<v Graham Cluley>You've been listening to Smashing Security with me, Graham Cluley, and huge thanks, of course, to Duck for joining us this week and this episode's sponsors, ESET, Vanta, and Action One, and also to the following fine folks who we are raising a glass to who include Chumbucket. That's a name gloriously unhinged, but no further comment to make on that.</v>

347
01:00:50.262 --> 01:01:00.027
<v Graham Cluley>Mikkel Goldschmidt sounds like a Scandinavian jeweler. Chris Pestle, Ashley Woodhall, Johan V, keeping his surname strictly classified.</v>

348
01:01:00.027 --> 01:01:09.793
<v Graham Cluley>MJ Erasmus, maybe they kill mice for a living. James S, another initial-only last name.</v>

349
01:01:09.793 --> 01:01:19.559
<v Graham Cluley>This podcast is practically a witness protection program. Someone here called Satan's Burgers, who we've got lots of questions for, starting with, can we see the menu please?</v>

350
01:01:19.559 --> 01:01:29.326
<v Graham Cluley>Alwin, Brian Jansen. Thank you all.</v>

351
01:01:29.326 --> 01:01:39.092
<v Graham Cluley>Everybody who's actually signed up for our Patreon, we really appreciate it from the bottom of our hearts and also from the bottom of our chum bucket, whatever that is. So those are all just a few members of Smashing Security Plus, which means that they get episodes ad-free earlier than the general public, and they can have their names pulled out at random to be mocked at the end of the show.</v>

352
01:01:39.092 --> 01:01:48.858
<v Graham Cluley>If you'd like to join Smashing Security Plus, just head over to smashingsecurity.com/plus for all of the details. And you can become a patron.</v>

353
01:01:48.858 --> 01:01:58.625
<v Graham Cluley>But you can also support the show in plenty of other ways which don't cost a penny. You can like and subscribe.</v>

354
01:01:58.625 --> 01:02:08.391
<v Graham Cluley>You can leave us a 5-star review wherever you listen as well. You can tell your friends about the show.</v>

355
01:02:08.391 --> 01:02:18.157
<v Graham Cluley>That's a really good one, actually. I like that.</v>

356
01:02:18.157 --> 01:02:27.922
<v Graham Cluley>Go and tell people, go and spread the word because every little bit helps. It makes all the effort worthwhile.</v>

357
01:02:27.922 --> 01:02:37.688
<v Graham Cluley>Well, I hope you have enjoyed this week's show and you will be with us again for next week's show. Until then, cheerio, bye-bye.</v>
