WEBVTT

1
00:00:13.641 --> 00:00:24.751
<v Danny Palmer>Yeah, it's just on the</v>

2
00:00:24.751 --> 00:00:35.859
<v Danny Palmer>bottom of your website.</v>

3
00:00:35.859 --> 00:00:43.359
<v Unknown>Smashing Security, episode 479.</v>

4
00:00:43.359 --> 00:00:50.859
<v Unknown>How a fake police officer nearly stole Graham's cryptocurrency with Graham Cluley and special guest Danny Palmer.</v>

5
00:00:50.859 --> 00:00:58.359
<v Unknown>Hello, hello, and welcome to Smashing Security, episode 479.</v>

6
00:00:58.359 --> 00:01:05.859
<v Unknown>My name's Graham Cluley.</v>

7
00:01:03.420 --> 00:01:10.040
<v Graham Cluley>Now, Danny, I've had a little bit of a run-in with, well, maybe with cybercriminals. I'm not sure.</v>

8
00:01:10.040 --> 00:01:16.659
<v Graham Cluley>Let me tell you something which happened to me just a few days ago.</v>

9
00:01:16.659 --> 00:01:25.920
<v Danny Palmer>Pray tell.</v>

10
00:01:25.920 --> 00:01:32.391
<v Graham Cluley>I got a phone call from somebody out of the blue, and I thought, I know that phone number. It said 0800 555 111, which is the number of Crimestoppers, of course.</v>

11
00:01:32.391 --> 00:01:38.861
<v Graham Cluley>Not that I'm regularly calling up.</v>

12
00:01:38.861 --> 00:01:46.040
<v Danny Palmer>Not that you're regularly involved with crime or crime</v>

13
00:01:46.040 --> 00:01:53.219
<v Danny Palmer>stopping, pans on anyway.</v>

14
00:01:53.219 --> 00:02:02.677
<v Graham Cluley>Not that I'm regularly the victim of crime. But anyway, this call came through and it said Crimestoppers. Oh, okay. So anyway, I took the call and this chap started speaking to me who sounded very much like he could work for the law. He could be a — and he introduced himself and said he was some sort of detective or something.</v>

15
00:02:02.677 --> 00:02:11.760
<v Danny Palmer>Did he sound like Gene Hunt or someone like that?</v>

16
00:02:03.287 --> 00:02:13.288
<v Graham Cluley>You can access their cryptocurrency if you know those 24 words. They said, is it possible that the hackers have managed to get that for you?</v>

17
00:02:11.760 --> 00:02:17.330
<v Graham Cluley>No, not as obvious as that. No sort of Ashes to Ashes or Life on Mars connection. But no, he said his name was Dave Pullen. Hello, this is Detective David Pullen here at the Crime Stoppers organisation. And he said he was working on a computer crime case. And he says, don't be alarmed, he says, you haven't done anything wrong, he said. And he put me at my ease that I wasn't in any trouble myself.</v>

18
00:02:13.288 --> 00:02:23.288
<v Graham Cluley>And I said, I think that's really unlikely because I haven't been dumb enough to paste it in anywhere. I have it securely.</v>

19
00:02:17.330 --> 00:02:22.899
<v Graham Cluley>But he said, maybe you can help me with an investigation. And I thought, well, maybe I can, you know, because I have helped the police before with some computer crime cases investigating various hacking groups. And I thought, well, it's a little bit unorthodox, but okay, all right. So he wants to talk to me. And he said that they had arrested someone on suspicion of some cybercrimes. And during the investigation of the digital evidence, they had found some information about me.</v>

20
00:02:22.899 --> 00:02:35.258
<v Unknown>Huh.</v>

21
00:02:23.288 --> 00:02:33.288
<v Graham Cluley>No, it's not tattooed on my buttocks or anything like that.</v>

22
00:02:35.258 --> 00:02:41.558
<v Graham Cluley>They had got my phone number and they'd got my personal email address. And he told me what that was and that was correct. And he said, and we've also found a scan of your passport and other information as well.</v>

23
00:02:41.558 --> 00:02:47.859
<v Graham Cluley>And I said, oh, that sounds bad. I said, tell me more.</v>

24
00:02:47.859 --> 00:02:56.766
<v Danny Palmer>Yeah. You said, oh, this sounds not great.</v>

25
00:02:51.889 --> 00:03:21.889
<v Danny Palmer>And I'm Danny Palmer.</v>

26
00:02:56.766 --> 00:03:04.296
<v Graham Cluley>No, it doesn't sound great, does it? And he told me the name of the chap who they'd arrested. And I'm not going to name him here on the podcast because it's quite possible this person is completely innocent. But he gave me the name of somebody and they said, do you know this person?</v>

27
00:03:04.296 --> 00:03:11.826
<v Graham Cluley>I said, no, I don't know him. He said, do you have any reason to think that he might have a vendetta against you? And I said, well, it is possible. I said, without being big-headed, it is possible he knows me, but I don't know him.</v>

28
00:03:11.826 --> 00:03:13.929
<v Danny Palmer>Don't you know who I am? You said—</v>

29
00:03:13.929 --> 00:03:21.429
<v Graham Cluley>I said, I didn't quite say, do you know who I am? But I've got a podcast, you know. But I said, I've been working in cybersecurity for 35 years or whatever and, you know, have a certain prominence. So it is possible. And I have received threats in the past from criminals.</v>

30
00:03:21.429 --> 00:03:28.929
<v Graham Cluley>And so it is possible there's been some kind of breach. And he said, well, have you shared your passport information with anyone? And I said, well, you know how it is sometimes, you know, I go and give talks around the world and sometimes people are booking me flights and sometimes people do ask for your passport. So much as I groan about it and grumble and how bloody hell, can this be allowed? And it shouldn't be.</v>

31
00:03:28.929 --> 00:03:36.429
<v Graham Cluley>And I tried to ensure that they delete it afterwards. It is possible that a scan of my passport is out there being held by somebody. So I said, yeah, well, it is possible they've got my passport. And they said, okay, all right. And they said, well, he said you sent it to him because you were booking an Airbnb in Manchester.</v>

32
00:03:36.429 --> 00:03:43.929
<v Graham Cluley>And I said, no, that's not true. I haven't booked an Airbnb in Manchester.</v>

33
00:04:13.270 --> 00:04:28.521
<v Danny Palmer>There's rumours of that I've heard anyway.</v>

34
00:04:16.800 --> 00:04:18.548
<v Danny Palmer>Well-known tourist destination, Manchester.</v>

35
00:04:18.548 --> 00:04:24.023
<v Graham Cluley>Well, you know, I mean, I imagine some people might want an Airbnb. Anyway, I don't have a need for an Airbnb in Manchester.</v>

36
00:04:24.023 --> 00:04:25.951
<v Danny Palmer>I believe our Prime Minister is from there.</v>

37
00:04:25.951 --> 00:04:55.951
<v Graham Cluley>He is?</v>

38
00:04:28.521 --> 00:04:37.358
<v Graham Cluley>Likes to describe himself as King of the North, which I imagine is actually rather upsetting to all the people for whom Manchester is considerably south of.</v>

39
00:04:37.358 --> 00:04:38.644
<v Unknown>Yeah.</v>

40
00:04:38.644 --> 00:04:46.144
<v Graham Cluley>Anyway, he likes to say that. So they said, okay, well, that's interesting.</v>

41
00:04:46.144 --> 00:04:53.644
<v Graham Cluley>They said, now, the other thing is that we have found some evidence that he had collected some information on people who own Trezor hardware wallets, which you can use to store your cryptocurrency on. And hands up, I think I've spoken about it on the podcast before.</v>

42
00:04:53.644 --> 00:05:01.144
<v Graham Cluley>I do have one of these hardware wallets for cryptocurrency. I bought it years and years and years ago.</v>

43
00:05:01.144 --> 00:05:08.644
<v Graham Cluley>I've only got a very small amount of cryptocurrency. If that weren't the case, then I wouldn't be doing a podcast.</v>

44
00:05:08.954 --> 00:05:10.315
<v Unknown>Yeah.</v>

45
00:05:10.315 --> 00:05:10.956
<v Graham Cluley>But, you know, I do have one of these wallet things and cybercriminals have found out that I've got one of these. I think at some point the Trezor mailing list was compromised. Maybe they were using a third party for their newsletters or something. Maybe it was like Mailchimp or something like that, because they know my email address because practically every day I get a phishing email claiming to come from Trezor, right? Asking me to do things. And it's like, oh, here we go again.</v>

46
00:05:10.956 --> 00:05:37.218
<v Unknown>You know.</v>

47
00:05:37.218 --> 00:05:40.528
<v Danny Palmer>Persistent, I suppose. There's that at least they've got going for them.</v>

48
00:05:40.528 --> 00:05:48.028
<v Graham Cluley>Right. So I thought, okay, it is quite possible that criminals know that I have one of these wallets.</v>

49
00:05:48.028 --> 00:05:55.528
<v Graham Cluley>And so he said to me, not only do they know that you have one of these wallets, they also have a 24-word seed key, which of course is the magic combination of words required to unlock someone's wallet so you can access their cryptocurrency if you know those 24 words, right? They said, is it possible that the hackers have managed to get that for you?</v>

50
00:05:55.528 --> 00:06:03.028
<v Graham Cluley>Because he appears to have a document which suggests that he's got it. And I said, I think that's really unlikely, because I haven't been dumb enough to paste it in anywhere.</v>

51
00:06:03.028 --> 00:06:10.528
<v Graham Cluley>You know, I have it securely. No, it's not tattooed on my buttocks or anything like that.</v>

52
00:06:20.528 --> 00:06:20.800
<v Unknown>Yeah.</v>

53
00:06:20.800 --> 00:06:22.550
<v Danny Palmer>It's just on the bottom of your website.</v>

54
00:06:22.550 --> 00:06:29.365
<v Graham Cluley>No, no, it's not. Right. So it's a secret.</v>

55
00:06:29.365 --> 00:06:36.180
<v Graham Cluley>And he said, okay, okay. He said, but if your cryptocurrency were compromised, would that make you suffer a significant financial loss?</v>

56
00:06:36.180 --> 00:06:36.680
<v Unknown>Hmm.</v>

57
00:06:36.680 --> 00:06:44.220
<v Graham Cluley>And I said, no, it wouldn't because I've hardly got any cryptocurrency. You know, it's really not very much at all. And he sounded a bit disappointed at that point.</v>

58
00:06:44.220 --> 00:06:51.759
<v Graham Cluley>And then he said, well, do you have any other cryptocurrency? And I thought, this is all getting a bit strange.</v>

59
00:06:51.759 --> 00:06:54.839
<v Danny Palmer>Yeah, this policeman's very interested in the contents of your wallet.</v>

60
00:06:54.839 --> 00:07:04.194
<v Graham Cluley>And particularly how much I might have in my cryptocurrency wallet. And so I said to him, I said, can you give me your name again?</v>

61
00:07:04.194 --> 00:07:13.550
<v Graham Cluley>And he gave me his name and I quickly had a little look, and sure enough, there he was on LinkedIn and he does appear to work for the police. Thought, interesting.</v>

62
00:07:13.550 --> 00:07:22.906
<v Graham Cluley>And I thought, he wouldn't be ringing from Crime Stoppers, would he? And he said, can you go to a police station within the next 24 hours and take a look at the photograph of the person we've taken into custody to see if you recognise him for any reason?</v>

63
00:07:22.906 --> 00:07:24.204
<v Unknown>Hmm.</v>

64
00:07:24.204 --> 00:07:31.377
<v Graham Cluley>I said, all right, okay, I could do that. And he said, just head to the main reception desk. And he gave me a crime reference number.</v>

65
00:07:31.377 --> 00:07:38.548
<v Graham Cluley>And I said, oh, I can go somewhere tomorrow. I said, I can go to a particular place.</v>

66
00:07:38.548 --> 00:07:43.098
<v Danny Palmer>Did they know which police station you'd have to go to?</v>

67
00:07:43.098 --> 00:07:50.598
<v Graham Cluley>And this was curious. So he said, is there a police station near you that you can go to? And I thought, I don't want to reveal where I live precisely.</v>

68
00:07:50.598 --> 00:07:58.098
<v Graham Cluley>So I gave the name of a town where I didn't live, where I knew there wasn't an open police office or department. And he says, okay. He says, I've just booked you in.</v>

69
00:07:58.098 --> 00:08:05.598
<v Graham Cluley>So you can go there, go up to the reception desk, quote this number. And he didn't ask me what county I lived in, for instance. I just named a place and I thought, wouldn't you ask for some more information?</v>

70
00:08:05.598 --> 00:08:13.098
<v Graham Cluley>Anyway, so I began to ask him some questions, whereupon the phone cut off and I thought, that's strange. And I looked in my email and there was an email claiming to come from the Metropolitan Police telling me that if I did not act upon their email, then potentially action could be taken against me because they said, you have to help us with this criminal. So there's the email saying you've potentially been a victim of crime.</v>

71
00:08:39.629 --> 00:08:44.812
<v Danny Palmer>If you don't help us investigate this crime, you are a criminal as well.</v>

72
00:08:44.812 --> 00:08:52.312
<v Graham Cluley>Potentially, yes. They could take action against me. And I looked in the headers of the email and although it had forged the headers, there was information in there. If you look in the raw header information, it was clear it had come from somewhere else.</v>

73
00:08:52.312 --> 00:08:59.812
<v Graham Cluley>And I thought, ooh, this is getting quite juicy. And by this point, of course, I'm really kicking myself because I wish I had said, I've got 4 million quid in my cryptocurrency wallet and wait for them to try and inveigle out of me my 24-word seed key, which surely was the thing that they're gonna do. So they're gonna say, well, can you read it out to us and we'll compare that to the one we have on our records? I think that was the plan.</v>

74
00:08:59.812 --> 00:09:07.312
<v Graham Cluley>I tried to call Crime Stoppers because I thought, well, their phone number's been forged. Couldn't get through to them. Just disaster. Contacted Action Fraud, which is the thing you are told to do.</v>

75
00:09:07.312 --> 00:09:14.812
<v Graham Cluley>I don't know what your experience has been reporting crimes to Action Fraud. They've rather blotted their copybook over the years. They're not the most efficient. Anyway, utterly unimpressed by their response, which was unhelpful because I shared all the email information and so forth and they just said, well, there's nothing here for us to investigate.</v>

76
00:09:54.727 --> 00:09:55.126
<v Unknown>Oh.</v>

77
00:09:55.126 --> 00:10:03.769
<v Graham Cluley>There is stuff here because presumably this person is going through a list of people who they know has Trezor cryptocurrency wallets on the phone, claiming to be the police and trying, I imagine, to get their seed keys out of them. I did my best, Danny.</v>

78
00:10:03.769 --> 00:10:12.413
<v Graham Cluley>I did my best. So that has been my unusual experience over the last few days.</v>

79
00:10:12.413 --> 00:10:21.056
<v Graham Cluley>Once again, I've failed to become a victim of cybercrime.</v>

80
00:10:21.056 --> 00:10:28.556
<v Danny Palmer>Whoever the individual or group behind this is, they're putting a lot of effort into this with the time it takes to do the phone calls, the research, that sort of thing.</v>

81
00:10:28.556 --> 00:10:36.056
<v Danny Palmer>I mean, they've left some holes in their plan, but yeah, this doesn't sound like it's some sort of amateur operation.</v>

82
00:10:36.056 --> 00:10:43.556
<v Danny Palmer>This is a group which seems to have a targeted goal to get this particular account using the information of this particular provider.</v>

83
00:10:43.556 --> 00:10:51.056
<v Danny Palmer>So they've got access to that and they're basically going down the list to try and get what they can from people.</v>

84
00:10:51.369 --> 00:10:57.307
<v Graham Cluley>It's possible they could — maybe they thought that would be a scalp, which would cause them some amusement.</v>

85
00:10:57.307 --> 00:11:03.246
<v Graham Cluley>It felt a little bit like Scattered Spider's tactics of ringing up customer service desks.</v>

86
00:11:03.246 --> 00:11:03.813
<v Danny Palmer>Yes.</v>

87
00:11:03.813 --> 00:11:10.113
<v Graham Cluley>I mean, this guy did sound — you know how policemen have a certain timbre? I mean, it sounded like that. You know, it wasn't like, hello, yeah, I am Chief Inspector Morse. It wasn't like that. You know, it was—</v>

88
00:11:10.113 --> 00:11:19.105
<v Danny Palmer>It wasn't 3 12-year-olds in a big coat, no.</v>

89
00:11:19.105 --> 00:11:26.605
<v Graham Cluley>Anyway, before we kick off, let's thank this week's wonderful sponsors. Arctic Wolf, NordLayer, and Vanta.</v>

90
00:11:26.605 --> 00:11:34.105
<v Graham Cluley>We'll be hearing more about them later on in the podcast. This week on Smashing Security.</v>

91
00:11:34.105 --> 00:11:41.605
<v Graham Cluley>We won't be talking about how people's Claude chats are turning up in Google search results. You'll hear no discussion of how Iranian hackers are being blamed for a multi-state cyberattack on US water systems, although Donald Trump is blaming the Democrats.</v>

92
00:11:41.605 --> 00:11:49.105
<v Graham Cluley>And we won't even mention how Google Maps allowed anyone for one whole day to fake satellite images of nuclear plants and floods before quietly pulling the feature. So Danny, what are you going to be talking about this week?</v>

93
00:12:04.960 --> 00:12:10.057
<v Danny Palmer>I'm going to be talking a bit about quite a major attack on the Department for Education and how this relates to schools and</v>

94
00:12:10.057 --> 00:12:15.154
<v Danny Palmer>universities and why they've become prime targets for hackers.</v>

95
00:12:15.154 --> 00:12:21.440
<v Graham Cluley>And I'm gonna be checking into a hotel where I'll be having rats with my cornflakes.</v>

96
00:12:21.440 --> 00:12:21.865
<v Unknown>Charming.</v>

97
00:12:21.865 --> 00:12:28.914
<v Graham Cluley>All this and much more coming up in this episode of Smashing Security.</v>

98
00:12:28.914 --> 00:12:35.964
<v Graham Cluley>Right, before we crack on any further, Joe and I want to take a moment to tell you about one of today's sponsors, Vanta.</v>

99
00:12:35.964 --> 00:12:42.756
<v Unknown>We've got a question for you. What's the thing that keeps you staring at the ceiling at 2 AM when it comes to your company security?</v>

100
00:12:42.756 --> 00:12:50.139
<v Graham Cluley>Is it wondering whether you've actually got the right controls in place? Whether one of your suppliers has been quietly compromised, or is it the truly soul-destroying one?</v>

101
00:12:50.139 --> 00:12:57.519
<v Graham Cluley>Why on earth are we still running our entire security programme out of a spreadsheet?</v>

102
00:12:57.519 --> 00:13:04.035
<v Unknown>If any of that hit a little too close to home, that's where Vanta comes in.</v>

103
00:13:04.035 --> 00:13:10.552
<v Unknown>Vanta takes all that tedious manual security grind — chasing down evidence, wrestling with questionnaires, updating the same cells for the thousandth time — and automates the whole thing.</v>

104
00:13:10.552 --> 00:13:25.283
<v Graham Cluley>Their trust management platform keeps a continuous eye on your systems. It pulls everything into one central place, and keeps your security programme audit-ready around the clock.</v>

105
00:13:25.283 --> 00:13:40.014
<v Graham Cluley>Yes, it uses AI, but the genuinely useful kind, flagging risks, streamlining evidence collection, and slotting into the tools your team already relies on. The upshot of this is you move faster, scale without the usual headaches, and maybe, just, just maybe, actually get a decent night's sleep.</v>

106
00:13:40.014 --> 00:13:45.190
<v Unknown>Sounds lush. Find out more and get started at vanta.com/smashing.</v>

107
00:13:45.190 --> 00:13:52.690
<v Graham Cluley>That's Vanta.com/smashing. And a big thank you to Vanta for supporting the show. So, chums, you're travelling for work. We've all done it, right?</v>

108
00:13:52.690 --> 00:14:00.190
<v Graham Cluley>Travel for work. You've had a long day. Maybe it's been a lengthy trip and you finally made it to your hotel and you dump your bag on the bed, you kick off your shoes, you've opened your laptop. First thing you're doing, priority number one, connect to the Wi-Fi.</v>

109
00:14:00.190 --> 00:14:07.690
<v Graham Cluley>And you know how it is connecting to a hotel network. Normally a little page will pop up asking you, can you confirm your room number? And sometimes they'd ask you for your surname as well. And you accept their terms and conditions that you're not gonna do anything naughty on the Wi-Fi.</v>

110
00:14:07.690 --> 00:14:15.190
<v Graham Cluley>And hopefully you're then online. It's fairly painless these days. I think most hotels have made it a lot easier than it used to be maybe 10 or 15 years ago.</v>

111
00:14:38.759 --> 00:14:48.181
<v Danny Palmer>Yeah, we're long past the point of where you have to go through about 5 different websites to get online and pay £20 for the privilege of an hour of internet, as it used to be back then.</v>

112
00:14:48.181 --> 00:14:55.681
<v Graham Cluley>So, you know, the job's done. Except according to security boffins who say for the last few months at least, there is a chance that something else has been happening to travellers logging into their hotel Wi-Fi.</v>

113
00:14:55.681 --> 00:15:03.181
<v Graham Cluley>Russia's Foreign Intelligence Service, the SVR, they run a hacking group variously known as APT29, Midnight Blizzard, or Cozy Bear. They are behind some of the biggest hacks of the last 10 years, including the SolarWinds supply chain attack, the hack of Microsoft's own corporate email, the breach at Hewlett-Packard Enterprise.</v>

114
00:15:03.181 --> 00:15:10.681
<v Graham Cluley>So these aren't script kiddies. These are serious cybercriminals with the backing of the Kremlin, professional spies funded by the Russian state.</v>

115
00:15:10.681 --> 00:15:18.181
<v Graham Cluley>And apparently they have gone on holiday. Apparently they could be at your local hostel.</v>

116
00:15:42.934 --> 00:15:43.657
<v Danny Palmer>Interesting.</v>

117
00:15:43.657 --> 00:15:49.467
<v Graham Cluley>Microsoft researchers have called this campaign Captive Crunch. And I have to say, that really tickled me.</v>

118
00:15:49.467 --> 00:15:55.278
<v Graham Cluley>Why would Captive Crunch tickle me, Danny? What's your hacking history knowledge?</v>

119
00:15:55.278 --> 00:15:57.923
<v Danny Palmer>Sounds very similar to a well-known breakfast cereal.</v>

120
00:15:57.923 --> 00:15:58.581
<v Unknown>Yes.</v>

121
00:15:58.581 --> 00:16:01.466
<v Graham Cluley>So in America, I don't know if it's sold here in the UK as well, there is of course the Captain Crunch breakfast cereal. And famously, it was the name of a hacker. Who I think took the name because he used to freak the phone system by—</v>

122
00:16:01.466 --> 00:16:13.389
<v Danny Palmer>Of course, yes.</v>

123
00:16:13.389 --> 00:16:21.115
<v Graham Cluley>Using the little whistle they gave away as a giveaway in a packet of Captain Crunch. That's way back when, decades and decades ago.</v>

124
00:16:21.115 --> 00:16:21.663
<v Danny Palmer>Yeah.</v>

125
00:16:21.663 --> 00:16:29.576
<v Graham Cluley>Frankly, I'm very impressed at Microsoft. This is probably the best piece of branding their marketing department has done in years, calling this Captive Crunch.</v>

126
00:16:29.576 --> 00:16:37.490
<v Graham Cluley>Someone definitely deserves a pay rise. This attack takes advantage of captive portals, which are the pages that help you to log into hotel Wi-Fi.</v>

127
00:16:37.490 --> 00:16:45.403
<v Graham Cluley>So when your laptop joins a hotel network via Wi-Fi, it asks the network, where is everything, right? I've joined.</v>

128
00:16:45.403 --> 00:16:46.129
<v Danny Palmer>Yeah.</v>

129
00:16:46.129 --> 00:16:53.731
<v Graham Cluley>Where can I find stuff? Because I want to go to Google, I want to go to Netflix or iPlayer or whatever it is you want to do.</v>

130
00:16:53.731 --> 00:17:01.333
<v Graham Cluley>And one of the things that the network provides is a phone book for the internet, which is the DNS, the Domain Name System, right?</v>

131
00:17:01.333 --> 00:17:02.158
<v Unknown>Yes.</v>

132
00:17:02.158 --> 00:17:05.065
<v Danny Palmer>And it's not quite as hefty as Yellow Pages, but—</v>

133
00:17:05.065 --> 00:17:12.565
<v Graham Cluley>Right. And this is the thing which translates your entry into your browser of microsoft.com into a sequence of numbers.</v>

134
00:17:12.565 --> 00:17:20.065
<v Graham Cluley>Websites are actually at numbers, IP addresses. You don't remember those, so you remember names instead.</v>

135
00:17:20.065 --> 00:17:27.565
<v Graham Cluley>So you go to microsoft.com or smashingsecurity.com instead. The point is though, if you connect to someone else's Wi-Fi network, your computer or phone trusts that network's DNS to give it the right answer, not to transmogrify microsoft.com, for instance, into the wrong sequence of numbers.</v>

136
00:17:27.565 --> 00:17:35.065
<v Graham Cluley>Because if that were to happen, your browser would be taken to a website and in the browser bar it would still say microsoft.com.</v>

137
00:17:54.771 --> 00:17:55.092
<v Unknown>Yeah.</v>

138
00:17:55.092 --> 00:18:00.138
<v Graham Cluley>But it would actually be on a different server instead, because you could be phished, malware could be</v>

139
00:18:00.138 --> 00:18:05.184
<v Graham Cluley>downloaded, you may hand over important credentials.</v>

140
00:18:05.184 --> 00:18:12.555
<v Danny Palmer>Yeah, I presume anyone doing this isn't doing it for no particular reason. They have malicious, nefarious goals for doing this.</v>

141
00:18:12.555 --> 00:18:20.055
<v Graham Cluley>Yes, it's absolute mischief-making. And so what these Russian hackers have done in this case is they've got into systems that run the hotel or conference centre Wi-Fi networks.</v>

142
00:18:20.055 --> 00:18:27.555
<v Graham Cluley>And once they're in there, they mess with the DNS for every single guest simultaneously. So there's no need to touch anyone's individual devices.</v>

143
00:18:27.555 --> 00:18:35.055
<v Graham Cluley>There's no need to send any phishing emails. You, the guest, connect to the hotel Wi-Fi.</v>

144
00:18:35.055 --> 00:18:42.555
<v Graham Cluley>Your laptop gets pointed at servers controlled by the hackers rather than the one which you intended to actually access instead.</v>

145
00:18:47.506 --> 00:18:57.449
<v Danny Palmer>That seems very economical of them. Phishing can be a lot of effort if you go around individuals.</v>

146
00:18:57.449 --> 00:19:07.392
<v Danny Palmer>Well, you're saying here, by doing what they're doing, they can get everyone within the hotel, which could be hundreds or maybe thousands of people depending on the size of it. So are they doing this remotely or is there someone looking suspicious in the cafe on a laptop?</v>

147
00:19:07.392 --> 00:19:13.869
<v Graham Cluley>I think this is being done on such a scale that there isn't someone lurking in the ice cream parlour of the hotel.</v>

148
00:19:13.869 --> 00:19:20.347
<v Graham Cluley>The boffins at ReliaQuest, they say they have found this at hotels in multiple US cities.</v>

149
00:19:20.347 --> 00:19:20.635
<v Unknown>Mm-hmm.</v>

150
00:19:20.635 --> 00:19:27.304
<v Graham Cluley>And internationally in Saudi Arabia and India, collecting information from diplomats, government employees, people who work in financial services, legal firms, healthcare, energy, all</v>

151
00:19:27.304 --> 00:19:33.972
<v Graham Cluley>kinds of people, anyone who travels for work.</v>

152
00:19:33.972 --> 00:19:43.960
<v Danny Palmer>So they're not just after holidaymakers, they're going specifically for venues and hotels around them, which are known to be hubs for particularly large events and conferences.</v>

153
00:19:43.960 --> 00:19:48.608
<v Graham Cluley>I think so. I think they're thinking that's where the juicy information is rather than the flea pit.</v>

154
00:19:48.608 --> 00:19:49.122
<v Danny Palmer>Hmm, interesting.</v>

155
00:19:49.122 --> 00:19:58.866
<v Graham Cluley>On the dark side of town. They're looking for people who either have money or they have information which would be useful.</v>

156
00:19:58.866 --> 00:20:08.613
<v Graham Cluley>Now you might think, well, this is fine, that's not a problem. I'll just hardcode Google's DNS server, which is 8.8.8.8, into my device.</v>

157
00:20:08.613 --> 00:20:18.357
<v Graham Cluley>I will bypass whatever DNS the hotel gives me. But because your DNS request from your phone or from your laptop still leaves your computer as plain readable traffic, the Wi-Fi gateway can intercept it.</v>

158
00:20:18.357 --> 00:20:18.731
<v Unknown>Yeah.</v>

159
00:20:18.731 --> 00:20:25.375
<v Graham Cluley>Never will go anywhere near Google's DNS. So you ask for Google's opinion, but in fact you get the hacker's answer instead.</v>

160
00:20:25.375 --> 00:20:26.113
<v Unknown>Huh.</v>

161
00:20:26.113 --> 00:20:27.396
<v Graham Cluley>So this is really bad.</v>

162
00:20:27.396 --> 00:20:30.686
<v Danny Palmer>It does sound bad. I'll be honest, Graham. It does.</v>

163
00:20:30.686 --> 00:20:31.087
<v Unknown>Yeah.</v>

164
00:20:31.087 --> 00:20:39.511
<v Graham Cluley>Because you can type in the correct URL of a website, you can choose it from your bookmarks and you'll be taken to a phishing site instead, or your software will be downloading a malicious update maybe. And it will still look like in the URL bar that you're on the real site.</v>

165
00:20:39.511 --> 00:20:47.934
<v Graham Cluley>So that would be bad enough, but there's worse. Oh, because it turns out some of the victims have also been hit by ClickFix attacks.</v>

166
00:20:47.934 --> 00:20:56.358
<v Graham Cluley>Now, we talked a little bit about ClickFix last week.</v>

167
00:20:56.358 --> 00:20:58.444
<v Danny Palmer>Yes, our friend ClickFix.</v>

168
00:20:58.444 --> 00:21:07.430
<v Graham Cluley>There's such a wave of these ClickFix things, aren't there? Anyone who hasn't already heard, just to very quickly describe it, it's where you have a popup or something asking you maybe to confirm that you're a human or to fix a technical problem.</v>

169
00:21:07.430 --> 00:21:16.414
<v Graham Cluley>Will you press this sequence of keys, which normally involves Windows+R on your Windows computer. Yeah.</v>

170
00:21:16.414 --> 00:21:23.162
<v Danny Palmer>Can you open this on your desktop and paste this code we've conveniently placed in here? Don't ask us what the code is, but just paste it in.</v>

171
00:21:21.618 --> 00:21:46.871
<v Danny Palmer>Another cereal, then.</v>

172
00:21:23.162 --> 00:21:29.909
<v Graham Cluley>Because you're effectively hacking your computer on behalf of the hackers by running a malicious piece of script.</v>

173
00:21:29.909 --> 00:21:39.145
<v Danny Palmer>But because you are doing it, your computer isn't gonna go, oh, hang on, what's going on here? So, oh, it's the operator, the usual user doing this. So there's no need to question that. Carry on.</v>

174
00:21:39.145 --> 00:21:49.145
<v Graham Cluley>And if you fall for</v>

175
00:21:46.871 --> 00:21:54.371
<v Graham Cluley>This is a Windows remote access Trojan that logs your keystrokes, which means they've got your passwords. It takes screenshots, records your microphone, your webcam.</v>

176
00:21:49.145 --> 00:21:59.145
<v Graham Cluley>that, you've just installed something</v>

177
00:21:54.371 --> 00:22:01.871
<v Graham Cluley>I mean, what could possibly go wrong in the privacy of your hotel room if your webcam and your microphone are being recorded? Steals passwords from your browser as well, exfiltrates files.</v>

178
00:21:59.145 --> 00:22:09.145
<v Graham Cluley>called Cornflake. Another great name.</v>

179
00:22:01.871 --> 00:22:09.371
<v Graham Cluley>Gives hackers remote access to your computer. And it does all this while disguising itself.</v>

180
00:22:09.371 --> 00:22:16.871
<v Graham Cluley>It claims to be a Windows service called Cloud Sync Service. Very sort of generic.</v>

181
00:22:20.073 --> 00:22:26.320
<v Danny Palmer>Well, that sounds suitably boring for me to not care about what that is doing on my laptop.</v>

182
00:22:26.320 --> 00:22:33.164
<v Graham Cluley>Yeah, it just claims to be a service which is needed to synchronise files with your cloud storage provider. So people are going to run that, particularly if they're working remotely.</v>

183
00:22:33.164 --> 00:22:40.009
<v Graham Cluley>They probably want to connect to their cloud storage provider. Many people think that's innocuous, and so they think there can't be anything dodgy with that.</v>

184
00:22:40.009 --> 00:22:46.853
<v Graham Cluley>And you might think, well, wouldn't my antivirus spot that? Well, it might.</v>

185
00:22:46.853 --> 00:22:47.676
<v Danny Palmer>Yes.</v>

186
00:22:47.676 --> 00:22:57.397
<v Graham Cluley>But this Cornflake thing is very good at maintaining persistence. It's a little bit like a dried cornflake on the bottom of your crockery, right?</v>

187
00:22:57.397 --> 00:23:07.118
<v Graham Cluley>You can't necessarily easily get rid of it. So if your antivirus removes it, or you try to remove it manually, it puts itself back.</v>

188
00:23:05.932 --> 00:23:20.885
<v Danny Palmer>Oh, Rice Krispies,</v>

189
00:23:07.118 --> 00:23:14.259
<v Danny Palmer>That's always the tricksy thing with these. I always find interesting about malware and Trojans.</v>

190
00:23:14.259 --> 00:23:21.401
<v Danny Palmer>Some of them are so clever, you do everything you want to get rid of it, then it's still — you close your front door, then you turn around and it's there standing right behind you again.</v>

191
00:23:20.885 --> 00:23:35.839
<v Danny Palmer>Weetos, Red Brick, Shredded Wheat.</v>

192
00:23:21.401 --> 00:23:31.401
<v Graham Cluley>And it doesn't stop there. Running alongside Cornflake is a PowerShell</v>

193
00:23:31.401 --> 00:23:41.401
<v Graham Cluley>info stealer. Do you want to have any guesses, Danny, as</v>

194
00:23:35.839 --> 00:23:40.425
<v Graham Cluley>This is ChocoShell, apparently. ChocoShell steals your —</v>

195
00:23:40.425 --> 00:23:44.579
<v Danny Palmer>That sounds like one of those off-brand ones you get at the discount supermarkets.</v>

196
00:23:41.401 --> 00:23:51.401
<v Graham Cluley>to what this one is called?</v>

197
00:23:44.579 --> 00:23:45.252
<v Unknown>That's it.</v>

198
00:23:45.252 --> 00:23:59.795
<v Graham Cluley>It's not Coco Pops. It's ChocoShell, which steals your Microsoft 365 session tokens, which means if you've got multifactor authentication in place, as you should do, on your Microsoft 365 account, the hackers can still access it using your session token.</v>

199
00:23:59.795 --> 00:24:14.336
<v Graham Cluley>And all of this is overseen by a control panel, another piece of software, Fruitstone. Frankly, that doesn't sound that appetising to me.</v>

200
00:24:14.336 --> 00:24:24.336
<v Danny Palmer>I think they're running out of ideas now in terms of —</v>

201
00:24:14.336 --> 00:24:44.336
<v Graham Cluley>I think it's Microsoft again.</v>

202
00:24:14.336 --> 00:24:24.336
<v Danny Palmer>I think it's the engineers there and at Reliant.</v>

203
00:24:14.336 --> 00:24:21.836
<v Graham Cluley>I think they can't be offering a decent breakfast to the technicians working at these security companies.</v>

204
00:24:21.836 --> 00:24:29.336
<v Graham Cluley>That is my only explanation.</v>

205
00:24:24.336 --> 00:24:34.336
<v Danny Palmer>so the people who've named these, is it Microsoft who've named these</v>

206
00:24:24.336 --> 00:24:34.336
<v Danny Palmer>It's what they get for breakfast when they turn</v>

207
00:24:29.336 --> 00:24:36.836
<v Graham Cluley>Fruitstone claims to be something called Cloud Sync Console by a fictional company called Acuity Systems Inc.</v>

208
00:24:34.336 --> 00:24:44.336
<v Danny Palmer>or is it the criminals who've named these this way?</v>

209
00:24:34.336 --> 00:24:44.336
<v Danny Palmer>up in the mornings at Redmond.</v>

210
00:24:36.836 --> 00:24:44.336
<v Graham Cluley>It's designed to look utterly boring.</v>

211
00:24:48.891 --> 00:24:58.296
<v Danny Palmer>As I said, yeah, you can see the offices of this fake company now because I'm seeing a lot of grey. A lot of beige. I'm getting very 1990s vibes from it.</v>

212
00:24:58.296 --> 00:25:05.796
<v Graham Cluley>So they don't want to draw attention to themselves. So what can you, dear listener, do about this?</v>

213
00:25:05.796 --> 00:25:13.296
<v Graham Cluley>Well, the single most effective thing, if you are a business, if you manage corporate devices, is to enforce the use of a full tunnel VPN. So it's not the kind of VPN where DNS can sort of sneak out round the edges, but it's properly full tunnel.</v>

214
00:25:13.296 --> 00:25:20.796
<v Graham Cluley>All traffic, including DNS requests, goes through your corporate network before it goes anywhere else. Okay.</v>

215
00:25:20.796 --> 00:25:28.296
<v Graham Cluley>So you're not paying any attention to what the hotel is saying to you.</v>

216
00:25:32.974 --> 00:25:33.553
<v Danny Palmer>Hmm.</v>

217
00:25:33.553 --> 00:25:36.894
<v Graham Cluley>So if you can do that, that's a great defence.</v>

218
00:25:36.894 --> 00:25:43.694
<v Danny Palmer>Okay. For businesses, yes.</v>

219
00:25:43.694 --> 00:25:50.497
<v Danny Palmer>I struggle to get people I know to even use 2FA or a password that isn't the word password. Well, maybe not to that extent, but sometimes solutions, because they can be perceived as so complex, people go, ooh, that sounds too complicated.</v>

220
00:25:50.497 --> 00:25:57.298
<v Danny Palmer>And they're unfortunately left open to things like this, I suppose.</v>

221
00:25:57.298 --> 00:26:04.798
<v Graham Cluley>So there is some advice for individuals as well. You maybe don't have that business solution.</v>

222
00:26:04.798 --> 00:26:12.298
<v Graham Cluley>What you can do, of course, is you could use your mobile phone as a hotspot. You could treat hotel Wi-Fi as something to be avoided.</v>

223
00:26:12.298 --> 00:26:19.798
<v Graham Cluley>If you must use hotel Wi-Fi, you can use a VPN that will give you some protection. Using a VPN is better than not using a VPN, but don't install anything.</v>

224
00:26:19.798 --> 00:26:27.298
<v Graham Cluley>Or if you get one of those click fix messages, if the captive portal asks you to install a driver or if it asks you to cut and paste something, you know, run to the hills effectively. If there's anything like that.</v>

225
00:26:32.262 --> 00:26:36.015
<v Danny Palmer>I don't think my hotels tend to ask me to install something on my computer when I get there.</v>

226
00:26:36.015 --> 00:26:36.816
<v Graham Cluley>No.</v>

227
00:26:36.816 --> 00:26:38.194
<v Danny Palmer>That's some sound advice.</v>

228
00:26:38.194 --> 00:26:44.167
<v Graham Cluley>So next time you're sitting in the hotel room hooking up to the Wi-Fi, just bear in mind you might not be the only one.</v>

229
00:26:44.167 --> 00:26:50.142
<v Graham Cluley>Getting connected, it could be the hackers as well.</v>

230
00:26:50.142 --> 00:26:52.948
<v Unknown>This week's episode is supported by NordLayer.</v>

231
00:26:52.948 --> 00:26:57.919
<v Graham Cluley>NordLayer. And before anyone says anything, no, it's not NordVPN.</v>

232
00:26:57.919 --> 00:26:59.105
<v Unknown>I wasn't gonna say that.</v>

233
00:26:59.105 --> 00:27:05.970
<v Graham Cluley>You were absolutely going to say that, Joe. They are both from Nord Security, but NordLayer is a completely different product.</v>

234
00:27:05.970 --> 00:27:12.833
<v Graham Cluley>NordVPN is for individuals. NordLayer is a network security platform built for businesses.</v>

235
00:27:12.833 --> 00:27:15.701
<v Unknown>Right, so what does NordLayer actually do?</v>

236
00:27:15.701 --> 00:27:23.717
<v Graham Cluley>Well, think about how your team works today. People logging in from home, from hotel Wi-Fi, from coffee shops, from wherever.</v>

237
00:27:23.717 --> 00:27:25.576
<v Unknown>From a sun lounger, hopefully.</v>

238
00:27:25.576 --> 00:27:32.340
<v Graham Cluley>You'd be lucky. And the moment someone logs into a company network over an unsecured connection, you've got a problem.</v>

239
00:27:32.340 --> 00:27:39.105
<v Graham Cluley>Credentials intercepted, phishing attacks, unauthorised access. It's a scary world out there for travelling workers.</v>

240
00:27:39.105 --> 00:27:40.628
<v Unknown>So NordLayer fixes that.</v>

241
00:27:40.628 --> 00:27:51.983
<v Graham Cluley>It gives you encrypted connectivity for your whole team from anywhere, up to 1 gigabyte per second with zero additional hardware required. But it goes well beyond just encrypting the connection.</v>

242
00:27:51.983 --> 00:28:03.338
<v Graham Cluley>You get centralised control over who can access what based on their identity, their device, whether their device is actually compliant. And if someone leaves the company, you revoke their access immediately.</v>

243
00:28:03.338 --> 00:28:13.338
<v Unknown>No more ex-employees</v>

244
00:28:03.338 --> 00:28:12.327
<v Graham Cluley>No more of that. And it will block malicious sites, risky downloads, dangerous domains.</v>

245
00:28:12.327 --> 00:28:21.317
<v Graham Cluley>And it can even detect shadow apps. So if someone on your team has started using some AI tool that your security team hasn't approved—</v>

246
00:28:13.338 --> 00:28:23.338
<v Unknown>still wandering around</v>

247
00:28:21.317 --> 00:28:22.326
<v Unknown>I'd never do that.</v>

248
00:28:22.326 --> 00:28:31.323
<v Graham Cluley>Yeah, well, whatever. NordLayer can spot that too. And there's no complex infrastructure to set up. Apparently, you can be up and running in just about 10 minutes.</v>

249
00:28:23.338 --> 00:28:33.338
<v Unknown>your systems 6 months later.</v>

250
00:28:31.323 --> 00:29:01.323
<v Unknown>10 minutes?</v>

251
00:28:31.323 --> 00:28:40.826
<v Graham Cluley>10 minutes. Plans start from just $8 per user per month. And right now, there is a summer sale.</v>

252
00:28:40.826 --> 00:28:50.329
<v Graham Cluley>New customers get up to 20% off annual plans until the end of August 2026. Use the code NLSUMMER26 at checkout.</v>

253
00:28:50.329 --> 00:28:56.971
<v Unknown>Whoa, all I have to do is type in that code at nordlayer.com/smashing and I can get a great deal? Let me write that down.</v>

254
00:28:56.971 --> 00:28:58.335
<v Graham Cluley>Yep, go ahead, write it down.</v>

255
00:28:58.335 --> 00:28:59.795
<v Unknown>What's the code again? I forgot.</v>

256
00:28:59.795 --> 00:29:02.761
<v Graham Cluley>Oh, Joe, NLSUMMER26.</v>

257
00:29:02.761 --> 00:29:07.173
<v Unknown>Got it. Off to nordlayer.com/smashing I go.</v>

258
00:29:07.173 --> 00:29:12.305
<v Graham Cluley>And thanks to NordLayer for supporting the show. Danny, what's your story for us this week?</v>

259
00:29:12.305 --> 00:29:22.086
<v Danny Palmer>Well, Graham, it's been a long time since I was at school, and I dunno how much has changed for sure, though I'm pretty sure that laptops and other internet-connected devices are much more commonplace than they were back when I was at school, when the computers were restricted to basically one room in the entire building. So this was, oh yeah, late '90s, early noughties. Just pre-internet age.</v>

260
00:29:22.086 --> 00:29:31.867
<v Danny Palmer>The only sort of connected devices, if you can call them that, we had back then was a Tamagotchi. That was about the most virtual distraction you could get in class pre-smartphone, which not astounds me, but kids these days, he says, sounding like a very old man, they grow up with, you know, internet-connected devices, smartphones, that sort of thing, which we'll get onto in a moment. But back to school, as it were.</v>

261
00:29:31.867 --> 00:30:00.269
<v Unknown>Yeah.</v>

262
00:30:00.269 --> 00:30:06.564
<v Danny Palmer>I'm sure that even the best, most student-friendly teacher now or back then would prefer to keep their students at arm's length.</v>

263
00:30:06.564 --> 00:30:12.858
<v Danny Palmer>As far as I know, you don't call your teacher by your first name.</v>

264
00:30:12.858 --> 00:30:14.849
<v Graham Cluley>I thought you meant like a personal hygiene issue.</v>

265
00:30:14.849 --> 00:30:23.630
<v Danny Palmer>Well, that's also bad. But anyway, I digress. But they'll be Mr. Smith or Ms.</v>

266
00:30:23.630 --> 00:30:32.410
<v Danny Palmer>Jones. You won't really know your teacher's first name. And I suppose Mr. Smith or Ms.</v>

267
00:30:32.410 --> 00:30:41.190
<v Danny Palmer>Jones would like to keep it that way. They would not want their information out there for nosy students to find out, 'cause, you know, it's the summer holidays right now. Kids need stuff to do, and, you know, kids like to find mischief, as far as I understand.</v>

268
00:30:41.190 --> 00:30:41.590
<v Graham Cluley>Yes.</v>

269
00:30:41.590 --> 00:30:51.590
<v Danny Palmer>Well, unfortunately for thousands of teachers and headteachers, they have had their names, job titles, and email addresses, and in some cases, phone numbers stolen in a hack, and</v>

270
00:30:51.590 --> 00:31:01.590
<v Danny Palmer>the crooks behind it have threatened to leak it. So imagine, for most people, having your personal data stolen is an annoyance, but for a teacher to have their</v>

271
00:31:01.590 --> 00:31:11.590
<v Danny Palmer>contact details leaked, there's probably some pranksters, ne'er-do-wells who might be tempted to use that for the wrong reasons.</v>

272
00:31:15.608 --> 00:31:16.347
<v Graham Cluley>You can imagine.</v>

273
00:31:16.347 --> 00:31:26.347
<v Danny Palmer>Some kids don't like being taught by teachers, I believe. But anyway, this is all potential worry, comes back to the UK government's Department for Education, for England specifically, 'cause I believe, you know, Scotland, Wales, Northern Ireland devolved out, which according to the Times revealed recently that hackers had obtained over 600,000 records in a cyberattack.</v>

274
00:31:26.347 --> 00:31:36.347
<v Danny Palmer>Now, the use of the word records is important here. It isn't the number of individuals which have been affected by the incident.</v>

275
00:31:36.347 --> 00:31:46.347
<v Danny Palmer>No, there aren't hundreds of thousands of teachers which have been affected by that. So I imagine if it was, that's basically every teacher in the country.</v>

276
00:31:54.237 --> 00:31:54.797
<v Unknown>Yeah.</v>

277
00:31:54.797 --> 00:32:02.297
<v Danny Palmer>But the lines of data which have been stolen in a hack against the Department for Education's help desk portal. The information on how this attack occurred is still not fully publicly out there, but there seem to be suggestions that it is like you experienced, Graham, sort of social engineering to try and get sort of usernames, passwords, that sort of thing for this help desk portal. But fortunately for those affected, the theft isn't thought to include bank details or sensitive personal information.</v>

278
00:32:02.297 --> 00:32:09.797
<v Danny Palmer>So there is that at least. I don't imagine you want little Jimmy Scrackett, let's say, getting their hands on teachers' bank details, because I'm sure that would be pretty bad. So that's good at least.</v>

279
00:32:09.797 --> 00:32:17.297
<v Danny Palmer>So that might be a result of the Department for Education, which said the attack was contained quickly. So whatever action it had taken, it reduced the amount of data which was accessed and stolen. So thumbs up there.</v>

280
00:32:17.297 --> 00:32:24.797
<v Danny Palmer>It seems like this attack was spotted fairly swiftly. It hasn't been going on for a long, long time, we think. So as any organisation which falls victim to a cyber incident would do, they have got the likes of the National Cyber Security Centre and the National Crime Agency involved.</v>

281
00:33:09.817 --> 00:33:19.859
<v Graham Cluley>So those are other arms of the government essentially helping this one investigate. Are you saying the resources of those investigatory bodies were more</v>

282
00:33:19.859 --> 00:33:29.901
<v Graham Cluley>preoccupied with 600,000 records of teachers being stolen than they were in me receiving a funny phone call from someone claiming to be a copper?</v>

283
00:33:29.901 --> 00:33:32.169
<v Danny Palmer>That's a good point, Graham. Maybe they were.</v>

284
00:33:32.169 --> 00:33:34.368
<v Graham Cluley>Have they got their priorities right? I have to ask.</v>

285
00:33:34.368 --> 00:33:41.868
<v Danny Palmer>I suppose they might be closer to each other than they are to your house because they ought to be in Whitehall. They can just walk around the corner to go have a chat, while with you, they'd have to sort of go somewhere else. If it's closer, we'll deal with it.</v>

286
00:33:41.868 --> 00:33:49.368
<v Danny Palmer>If it isn't, nah, maybe not. Interestingly though, as a side note, as well as the teachers, there are reports that this incident has also involved details of some police as well, which have been involved as well. So whole different thing here, but all related to the same incident, which for the government, for the Department for Education, it's likely to be considered something of an embarrassment because it is a major part of the government.</v>

287
00:33:49.368 --> 00:33:56.868
<v Danny Palmer>It's been hit by a cyberattack, which is, you know, considering the government, as previously mentioned, government bodies very vocal about the threat of cyberattacks and cyber risk, for them to be targeted by one is, well, probably not unexpected because governments are likely a big scalp, but having been hit by one takes a little bit of explaining, I imagine. So who is behind this attack? Well, it's been reported that the culprit is a previously unknown hacking group, which calls itself Exfil Squad, which have been posting snippets of stolen data on their leak site.</v>

288
00:33:56.868 --> 00:34:04.368
<v Danny Palmer>There's, again, information about these is patchy, but they sound kind of similar to your Scattered Spider type operation where it seems they've got together to do this, to make money, to cause trouble. And make money is what they want to do here because according to the Guardian newspaper, these hackers have demanded a payment from the Department of Education not to publish the whole vast swathes of the 600,000 bits of data they have stolen.</v>

289
00:35:18.255 --> 00:35:25.489
<v Graham Cluley>It's a familiar story of pay the ransom, otherwise we're going to publish the data which we've stolen from your servers.</v>

290
00:35:25.489 --> 00:35:32.989
<v Danny Palmer>Exactly. You know, it's essentially like ransomware tactics, but as appears to be increasingly common for extortion groups, they cut out the middleman, middle software.</v>

291
00:35:32.989 --> 00:35:40.489
<v Danny Palmer>The ransomware element of it. They don't encrypt your files.</v>

292
00:35:40.489 --> 00:35:47.989
<v Danny Palmer>They just go in, steal it, and say, we have it, now pay us. Which I guess for the attackers takes less time because you're not having to sort of slowly move your way around the network to encrypt everything you need, and probably a bit less effort on their part.</v>

293
00:35:47.989 --> 00:35:55.489
<v Danny Palmer>For ransomware, for example, you need to have some ransomware under your belt to sort of shove into the system you're trying to compromise.</v>

294
00:36:03.081 --> 00:36:03.563
<v Unknown>Hmm.</v>

295
00:36:03.563 --> 00:36:11.063
<v Danny Palmer>Well, if you're stealing data, you can just use a stolen login account. Click fix vulnerabilities, that sort of thing. So it sounds like it's part of an efficiency drive by the attackers here.</v>

296
00:36:11.063 --> 00:36:18.563
<v Danny Palmer>Also, there is just the fact that you know many attackers are just lazy. They want to do the least amount of work possible to make the most money they can, and in this case, just stealing the data is what they're doing. So they've gone in here and they've stolen this data and threatened to publish it.</v>

297
00:36:18.563 --> 00:36:26.063
<v Danny Palmer>The statement which has been posted in the media in articles about this is — the attackers say, and I quote, the payment we request of you is simply a rounding error compared to the litigation costs of your data leaking. Be smart and just pay. Which is polite, isn't it?</v>

298
00:36:26.063 --> 00:36:33.563
<v Danny Palmer>I just find it fascinating, these cybercriminal groups, they always try to make it sound like they are doing you a favour.</v>

299
00:36:56.858 --> 00:36:57.291
<v Unknown>Yes.</v>

300
00:36:57.291 --> 00:37:02.809
<v Danny Palmer>Like, oh yes. Oh, we discovered your security is terrible. And we'll help you fix it if you pay us money.</v>

301
00:37:02.809 --> 00:37:08.329
<v Danny Palmer>And if you don't, well, we're just gonna make it even worse. Yes.</v>

302
00:37:08.329 --> 00:37:16.132
<v Graham Cluley>You're a client of theirs. They've done some consultancy. You hadn't actually employed them, but they've done some consultancy on your network security.</v>

303
00:37:16.132 --> 00:37:23.632
<v Danny Palmer>Yeah. It wouldn't really work the other way. Imagine going to the supermarket and a shop member of staff threatening you with a big stick if you don't buy a certain product from the shelf.</v>

304
00:37:23.632 --> 00:37:31.132
<v Danny Palmer>But that's what they're doing here, essentially. They've threatened to expose this information about teachers and headteachers, which, as established, isn't the most sort of sensitive information out there, but it would be annoying for those people who are affected, not just because they could become targeted by scams, but also, yeah, there's the potential for mischievous students playing pranks on them, as you imagine they might do. But in addition to this, this leak has also contained information about members of staff at universities as well.</v>

305
00:37:31.132 --> 00:37:38.632
<v Danny Palmer>So they are under the remit of the Department for Education, but this is beyond a bit from your schools and your colleges. And I'm sure listeners to Smashing Security are likely aware, the university has had something of a torrid time when it comes to cyberattacks this year. There've been a range of high-profile incidents around the world.</v>

306
00:37:38.632 --> 00:37:46.132
<v Danny Palmer>Here in the UK, the University of Nottingham received a significant cyberattack where a lot of data was breached. And it all comes at a time when there's lots of stories in the news about students not being very happy with the services they're getting from university anyway, sometimes because it costs a lot of money. And if you are not getting your education because someone's ransomwared your university, that's not good for anyone.</v>

307
00:38:41.047 --> 00:38:41.929
<v Unknown>No.</v>

308
00:38:41.929 --> 00:38:52.181
<v Danny Palmer>So there have been several reports in recent months about a significant rise of extortion attacks like this targeting universities, as well as ransomware attacks against higher education and schools. So why is this?</v>

309
00:38:52.181 --> 00:39:02.434
<v Danny Palmer>Well, there's a combination of reasons really. So back when I was at university, again, we've established a long time ago.</v>

310
00:39:02.434 --> 00:39:06.762
<v Graham Cluley>Yeah, it was about 10, 20 years after they invented the wheel. I remember. Yeah.</v>

311
00:39:06.762 --> 00:39:08.846
<v Danny Palmer>Yes. Got to university on horseback. Yeah. We had internet, but it was really, really restricted. I couldn't use a connection from my student room to play any online games, which I don't think would go down well these days. I don't imagine you could tell teenagers getting into university that they can't play Call of Duty or FIFA or whatever it is they play these days. And we still accessed most resources in paper and book form, which again, suddenly makes me sound really ancient. So fast forward to 2026 and things are very different.</v>

312
00:39:08.846 --> 00:39:38.846
<v Unknown>Yeah.</v>

313
00:39:40.530 --> 00:39:50.047
<v Danny Palmer>Universities are very, very, very online. They rely on the internet for so many things, which is one of the reasons why they're a top target for attackers.</v>

314
00:39:50.047 --> 00:39:59.565
<v Danny Palmer>My contract at Security Magazine has recently ended and I'm back to being a freelancer now. But just before I left, I drafted an interview with Keith Joy.</v>

315
00:39:59.565 --> 00:40:09.081
<v Danny Palmer>He's head of technology and digital at the University of Arts London, which is one of the most highly rated arts and creative universities in the world.</v>

316
00:40:09.081 --> 00:40:09.402
<v Graham Cluley>Okay.</v>

317
00:40:09.402 --> 00:40:19.711
<v Danny Palmer>He told me that nowadays university networks are set up with the expectation that each individual student will come in with maybe 5 devices connected to the Wi-Fi. I couldn't even imagine that back when I was at university.</v>

318
00:40:19.711 --> 00:40:30.021
<v Danny Palmer>You had a laptop and that was it. Put simply, students these days, like many of us, expect to be online all the time.</v>

319
00:40:30.021 --> 00:40:30.166
<v Graham Cluley>Yeah.</v>

320
00:40:30.166 --> 00:40:35.579
<v Danny Palmer>And these university campuses can be home to tens of thousands of students and staff, of course.</v>

321
00:40:35.579 --> 00:40:40.990
<v Danny Palmer>They all have usernames, logins, accounts, cloud access, that sort of thing.</v>

322
00:40:40.990 --> 00:40:41.199
<v Unknown>Yeah.</v>

323
00:40:41.199 --> 00:40:48.166
<v Danny Palmer>So like any other organisation, they will try to put security controls around that. However, unlike a corporate environment, those laptops that are being used by students — I don't think they would react well saying, "Welcome to university, can we take your laptop?</v>

324
00:40:48.166 --> 00:40:55.132
<v Danny Palmer>Because we're going to tell you what you can and can't do on your personal laptop."</v>

325
00:40:55.132 --> 00:41:02.998
<v Graham Cluley>We're going to lock it down for you. We're going to take away all the fun stuff.</v>

326
00:41:02.998 --> 00:41:10.536
<v Danny Palmer>Yes. But no, they want to take their personal laptops so they can use them in their own time.</v>

327
00:41:10.536 --> 00:41:18.074
<v Danny Palmer>Students are online a lot, so there's a lot of risk for social engineering leading to increased risks of cyberattacks.</v>

328
00:41:18.074 --> 00:41:18.347
<v Graham Cluley>Yeah.</v>

329
00:41:18.347 --> 00:41:27.409
<v Danny Palmer>Cybercriminals know that. They know the students are very online and they know that because these students are paying a lot to attend universities, these universities also can't be in a position where they can be locked down by ransomware or students feel like they've been let down by their data being breached and stolen, which is why unfortunately it remains extremely common for universities to pay ransom demands to cybercriminal groups.</v>

330
00:41:27.409 --> 00:41:36.469
<v Danny Palmer>It's an interesting one. I feel like for all intents and purposes, a university does act quite like a corporate environment.</v>

331
00:41:36.469 --> 00:41:45.530
<v Danny Palmer>But as mentioned, you can't have that entirely locked down thing going on, so it's a bit of an open goal.</v>

332
00:41:45.530 --> 00:41:56.898
<v Graham Cluley>It's a very difficult situation where you've got potentially thousands of students coming in</v>

333
00:41:56.898 --> 00:42:08.266
<v Graham Cluley>with, as you mentioned, thousands and thousands of devices connecting to the network.</v>

334
00:42:08.266 --> 00:42:15.766
<v Danny Palmer>And it's interesting as well. So when you think about it, a business will have people coming and going every year. For universities, a third of people come and go at the same time.</v>

335
00:42:15.766 --> 00:42:23.266
<v Danny Palmer>So you have to have all these new accounts, new setups. That sort of time is probably another big window for attackers as well. You know, "Oh, welcome to university, click here to sign up" — oh, it's a phishing email.</v>

336
00:42:23.266 --> 00:42:30.766
<v Danny Palmer>So yeah, unfortunately extortion, ransomware — these remain big issues for the university sector. Education is struggling with this and still is. A lot of it comes down to resources.</v>

337
00:42:30.766 --> 00:42:38.266
<v Danny Palmer>I imagine they're not really thinking about cybersecurity until it's too late. It feels like, as is often the case, this is ongoing. As I said, there is a ransom demand, but I would be very, very, very, very surprised if the government paid a ransom to some cybercriminals.</v>

338
00:43:01.606 --> 00:43:07.719
<v Graham Cluley>I think you're right. I think they are unlikely to. It sounds like the hackers are giving it a good try.</v>

339
00:43:07.719 --> 00:43:15.101
<v Danny Palmer>No, it's the school holidays right now. Hopefully some lessons will be learned before the new academic year kicks off in September.</v>

340
00:43:15.101 --> 00:43:18.871
<v Graham Cluley>I see what you did there, Danny. Lessons will be learned, you hope.</v>

341
00:43:18.871 --> 00:43:26.023
<v Danny Palmer>That's the reporter hack in me, isn't it?</v>

342
00:43:26.023 --> 00:43:33.173
<v Danny Palmer>Every journalist reporter — essentially some base part of them wants to be a headline writer for The Sun.</v>

343
00:43:33.173 --> 00:43:37.431
<v Unknown>Graham, am I right in thinking that Arctic Wolf are sponsoring the show this week?</v>

344
00:43:37.431 --> 00:43:45.429
<v Graham Cluley>You are right, Joe.</v>

345
00:43:45.429 --> 00:43:53.429
<v Graham Cluley>They've just published a new report, 2026 State of the Cybersecurity Attack Surface, and they analysed over 800,000 real IT assets to find out how exposed organisations actually are.</v>

346
00:43:53.429 --> 00:43:56.478
<v Unknown>And I'm guessing everything is hunky-dory?</v>

347
00:43:56.478 --> 00:43:59.027
<v Graham Cluley>No, not so much. The reality is they found 1 in 3 IT assets is missing at least one critical security control.</v>

348
00:43:59.027 --> 00:44:06.784
<v Unknown>1 in 3? That's terrible.</v>

349
00:44:06.784 --> 00:44:16.563
<v Graham Cluley>Isn't it just? 10% of assets have no endpoint security at all. 17% are completely invisible to the tools that are supposed to be monitoring them.</v>

350
00:44:16.563 --> 00:44:19.608
<v Unknown>So the tools don't even know those assets exist?</v>

351
00:44:19.608 --> 00:44:25.313
<v Graham Cluley>Right. Ghost assets wandering around your network unprotected. Unmonitored.</v>

352
00:44:25.313 --> 00:44:30.362
<v Unknown>Like a retired geography teacher who's somehow still on the school network.</v>

353
00:44:30.362 --> 00:44:35.409
<v Unknown>Nobody added him, nobody removed him, and he's been quietly in there for 11 years downloading maps of Paraguay.</v>

354
00:44:35.409 --> 00:44:43.356
<v Graham Cluley>Yeah, yeah, yeah, I guess so, Joe. The point is, your attackers will find him before you do because they are specifically looking for the forgotten, the unpatched, the invisible.</v>

355
00:44:43.356 --> 00:44:51.302
<v Graham Cluley>That's the path of least resistance.</v>

356
00:44:51.302 --> 00:44:54.411
<v Unknown>So what does the report tell us to actually do about it?</v>

357
00:44:54.411 --> 00:45:07.298
<v Graham Cluley>Arctic Wolf's report covers how to prioritise the exposures that actually matter, cut through all that noise, and verify that when you fix something, it actually stays fixed. And the report is free to download. Free!</v>

358
00:45:07.298 --> 00:45:09.181
<v Unknown>I like that. Where do I get it?</v>

359
00:45:09.181 --> 00:45:10.710
<v Graham Cluley>smashingsecurity.com/arcticwolf.</v>

360
00:45:10.710 --> 00:45:16.940
<v Unknown>That's smashingsecurity.com/arcticwolf. And thanks to Arctic Wolf for supporting the show.</v>

361
00:45:16.940 --> 00:45:23.170
<v Unknown>And please keep an eye on your IT assets and retired geography teachers.</v>

362
00:45:23.170 --> 00:45:26.715
<v Graham Cluley>And welcome back, and you join us at our favourite part of the show, the part of the show that we like to call Pick of the Week. Pick of the Week.</v>

363
00:45:26.715 --> 00:45:56.715
<v Danny Palmer>Pick of the Week.</v>

364
00:45:26.715 --> 00:45:35.112
<v Graham Cluley>Pick of the Week is the part of the show where everyone chooses something they like. Could be a funny story, a book that they've read, a TV show, a movie, a record, a podcast, a website, or an app, whatever they wish.</v>

365
00:45:35.112 --> 00:45:43.512
<v Graham Cluley>It doesn't have to be security-related necessarily. Well, my pick of the week this week is not security-related.</v>

366
00:45:43.512 --> 00:45:51.909
<v Graham Cluley>In fact, my pick of the week this week may not actually be a pick of the week.</v>

367
00:45:51.909 --> 00:45:52.952
<v Danny Palmer>Oh no.</v>

368
00:45:52.952 --> 00:45:57.583
<v Graham Cluley>My pick of the week may actually be a nitpick of the week.</v>

369
00:45:57.583 --> 00:46:01.286
<v Danny Palmer>Did you get a new angry jingle set up for that?</v>

370
00:46:01.286 --> 00:46:09.344
<v Graham Cluley>There is a special sound for nitpick of the week, which our listeners are listening to right now. They aren't as common as the picks of the week. Look, I can say pick of the week and I can say nitpick of the week.</v>

371
00:46:09.344 --> 00:46:17.402
<v Graham Cluley>Listen to that. Can you tell the difference?</v>

372
00:46:17.402 --> 00:46:19.742
<v Danny Palmer>Definitely.</v>

373
00:46:19.742 --> 00:46:23.356
<v Graham Cluley>Anyway, I'm a bit of a Doctor Who fan. I may have mentioned it occasionally.</v>

374
00:46:23.356 --> 00:46:24.277
<v Danny Palmer>You do surprise me, Graham.</v>

375
00:46:24.277 --> 00:46:26.295
<v Graham Cluley>I think you're a bit of a Doctor Who fan too, aren't you, Danny?</v>

376
00:46:26.295 --> 00:46:36.280
<v Danny Palmer>Yes, yes. I believe the first time we met in person, we ended up having quite a long discussion about this sort of thing, much to the confusion of the people around us.</v>

377
00:46:36.280 --> 00:46:46.280
<v Graham Cluley>Anyway, I was recently made aware of a book which has come out called When I Say Run, Run, which is a book which goes behind the scenes of Doctor Who between 1966 and 1969, which for me, see, I love black and white 1960s Doctor Who. Classic Doctor Who is what I like. That's when Patrick Troughton, the 2nd Doctor, he was in charge of the TARDIS back then.</v>

378
00:46:46.280 --> 00:46:56.280
<v Graham Cluley>And this book is written by a guy called Thom Dexter. And I read a review of it and I thought, this book sounds great. 'Cause I'm interested in all the behind-the-scenes stuff more than the actual programme.</v>

379
00:46:56.280 --> 00:47:06.280
<v Graham Cluley>I think I'm more interested in the production of Doctor Who. And I thought, oh, that's really interesting. I hadn't heard about that before.</v>

380
00:47:15.280 --> 00:47:19.407
<v Danny Palmer>You want to know what materials those enemies are made out of?</v>

381
00:47:19.407 --> 00:47:26.295
<v Graham Cluley>So I thought it'd be interesting because it'd be like a diary of the making of Doctor Who in the late '60s. And I thought, fantastic.</v>

382
00:47:26.295 --> 00:47:33.184
<v Graham Cluley>So I ordered it. And it was only after I ordered it that I found that maybe the wool had been pulled over my eyes a little.</v>

383
00:47:33.184 --> 00:47:34.161
<v Unknown>Oh no.</v>

384
00:47:34.161 --> 00:47:41.793
<v Graham Cluley>Because the author of the book is not Thom Dexter. That is a nom de plume.</v>

385
00:47:41.793 --> 00:47:49.427
<v Graham Cluley>The actual author of the book is a guy called Adrian Rigglesford. And he just happens to use the name Thom Dexter now.</v>

386
00:47:49.427 --> 00:47:57.059
<v Graham Cluley>And if I knew that Adrian Rigglesford had written the book, it's probably quite likely I would have paused before buying it.</v>

387
00:47:57.059 --> 00:47:57.795
<v Danny Palmer>Interesting.</v>

388
00:47:57.795 --> 00:48:05.735
<v Graham Cluley>Because his is a name that is known to me. Because he's rather a controversial chap. Now—</v>

389
00:48:05.735 --> 00:48:08.304
<v Danny Palmer>Is he your sworn enemy? Is that the problem?</v>

390
00:48:08.304 --> 00:48:13.925
<v Graham Cluley>He's not. No, I do have a nemesis, but it isn't Adrian Ringle's foot. Well, maybe one day we'll talk about my nemesis.</v>

391
00:48:13.925 --> 00:48:15.692
<v Danny Palmer>The master.</v>

392
00:48:15.692 --> 00:48:23.192
<v Graham Cluley>Well, 1999, Stanley Kubrick, right? Fantastic film director, one of the greatest film directors of all time.</v>

393
00:48:23.192 --> 00:48:30.692
<v Graham Cluley>He died in 1999. Six months later in the TV Times, which is not a publication I regularly purchase or indeed have ever purchased in my life, but six months just after the death of Stanley Kubrick, they ran what they called a world-exclusive last interview conducted with Kubrick by Adrian Rigglesford on the set of Eyes Wide Shut.</v>

394
00:48:30.692 --> 00:48:38.192
<v Graham Cluley>And this came out. And one of the people who read that interview was Kubrick's personal assistant, who said, hang on a minute, this doesn't seem right to me.</v>

395
00:48:38.192 --> 00:48:45.692
<v Graham Cluley>I would surely have known about this interview taking place on the set.</v>

396
00:49:01.208 --> 00:49:31.208
<v Danny Palmer>Yeah, you'd think they'd know.</v>

397
00:49:01.208 --> 00:49:03.418
<v Unknown>Yeah.</v>

398
00:49:03.418 --> 00:49:10.918
<v Graham Cluley>Yeah. And furthermore, he said, these quotes from Stanley Kubrick don't sound like Kubrick at all.</v>

399
00:49:03.418 --> 00:49:33.418
<v Unknown>Yeah.</v>

400
00:49:10.918 --> 00:49:18.418
<v Graham Cluley>And so he challenged the magazine and the TV Times initially resisted and said, well, the interview was tape recorded, but they never provided a recording. And eventually TV Times admitted that it had been conned by Rigglesford and they published an apology.</v>

401
00:49:18.418 --> 00:49:25.918
<v Graham Cluley>It was a completely fantasised fake interview. And it subsequently emerged because this assistant of Stanley Kubrick dug a little deeper.</v>

402
00:49:25.918 --> 00:49:33.418
<v Graham Cluley>He obviously had the bit between his teeth.</v>

403
00:49:39.188 --> 00:49:47.061
<v Graham Cluley>It emerged that Rigglesford had come out with all kinds of interviews over the years with dead stars of Doctor Who, interviews that no one had ever known had taken place.</v>

404
00:49:47.061 --> 00:49:54.932
<v Graham Cluley>But he wrote these articles up of like the long-lost interview with so-and-so, which he claimed to have done.</v>

405
00:49:54.932 --> 00:49:56.909
<v Danny Palmer>So weird.</v>

406
00:49:56.909 --> 00:50:03.831
<v Graham Cluley>And these were viewed with some suspicion by fans.</v>

407
00:50:03.831 --> 00:50:10.755
<v Graham Cluley>And then he was jailed for stealing 50,000 photos from the Daily Mail photo library and selling them to memorabilia shops in London.</v>

408
00:50:10.755 --> 00:50:13.326
<v Danny Palmer>So would this have been physical photos as well?</v>

409
00:50:13.326 --> 00:50:18.996
<v Graham Cluley>I think he was actually stealing physical photographic prints from the Daily Mail's library.</v>

410
00:50:18.996 --> 00:50:24.393
<v Danny Palmer>50,000 is a lot. Didn't all come out in just one big bag labelled swag, I imagine, but—</v>

411
00:50:24.393 --> 00:50:31.893
<v Graham Cluley>So this guy has got a bit of a reputation in Doctor Who fandom. So already being a bit of a Doctor Who nerd, I already knew about him and the controversy around him. And you would've thought after that run-in, he maybe would've chosen a different career.</v>

412
00:50:31.893 --> 00:50:39.393
<v Graham Cluley>He would've become a landscape gardener. He would've become a bus conductor. He would've done something else.</v>

413
00:50:39.393 --> 00:50:46.893
<v Graham Cluley>But it turns out that he actually threw himself back into Doctor Who fandom, writing stuff but under a different name. And it's only just been found out. The link has been made.</v>

414
00:50:46.893 --> 00:50:54.393
<v Graham Cluley>So hang on a minute. Now he's writing books which claim again to be factual reports of Doctor Who in the 1960s. And this mug here may not have lost his cryptocurrency, but he lost his 15 quid buying a book.</v>

415
00:51:10.538 --> 00:51:11.099
<v Danny Palmer>Yeah.</v>

416
00:51:11.099 --> 00:51:20.920
<v Graham Cluley>Thinking I could trust it. Now, first of all, the book has got a beautiful cover, right? It's a lovely cover. It's a very nice piece of art. I'm very impressed by that, by Geoff Cummins. Nothing wrong with him.</v>

417
00:51:20.920 --> 00:51:23.710
<v Danny Palmer>At least he's commissioned a proper artist to do the cover then.</v>

418
00:51:23.710 --> 00:51:33.710
<v Graham Cluley>Yeah, exactly. They haven't used AI.</v>

419
00:51:33.710 --> 00:51:43.710
<v Graham Cluley>And I have enjoyed reading the book, but my experience of the book is soured somewhat by not knowing if I can trust a word of it because of this guy's reputation. And I'm not saying people can't be rehabilitated, but when it comes to producing something which is a historical document, if you want to be taken seriously for talking about something which happened 60, 70 years ago or more, then I think how you behaved in the past, how you have carried yourself, carries some weight.</v>

420
00:51:43.710 --> 00:51:53.710
<v Graham Cluley>And so I'm afraid this book, which is called When I Say Run, Run by Thom Dexter in quotes, has to be my nitpick of the week. And I also, apparently the publisher knew his real identity.</v>

421
00:52:12.202 --> 00:52:14.255
<v Danny Palmer>Huh.</v>

422
00:52:14.255 --> 00:52:25.864
<v Graham Cluley>And they only came clean about it when they were challenged and they said, well, we rigorously checked the content ourselves for factual accuracy. And you just think, well, today, couldn't you have given me the ability to make an informed decision before buying it?</v>

423
00:52:25.864 --> 00:52:37.474
<v Graham Cluley>So I'm a bit annoyed about it. And that is my nitpick of the week.</v>

424
00:52:37.474 --> 00:52:52.184
<v Danny Palmer>I've just opened the Wikipedia page for old Adrian and yeah, it's never a good sign when probably half of it is under the banner controversies for someone. I mean, but no, that is a— that does sound like a really interesting read.</v>

425
00:52:52.184 --> 00:53:06.894
<v Danny Palmer>It's like yourself, you know, I have an interest in these older ones because I'm such a cool guy. A few years ago when I got married, part of my stag party was going to Riverside Studios to watch on the big screen some episodes of The Tenth Planet.</v>

426
00:53:06.894 --> 00:53:07.717
<v Unknown>Oh, yes.</v>

427
00:53:07.717 --> 00:53:08.762
<v Graham Cluley>Oh my goodness.</v>

428
00:53:08.762 --> 00:53:10.641
<v Danny Palmer>Yeah. Back to back.</v>

429
00:53:10.641 --> 00:53:19.989
<v Graham Cluley>So for people who don't know, The Tenth Planet was the last ever episode of William Hartnell, the original Doctor Who, which introduced the Cybermen back when they were Mondasian Cybermen, which is when they had cloth faces rather than being made out of metal. And wow.</v>

430
00:53:19.989 --> 00:53:29.338
<v Graham Cluley>That was your stag party.</v>

431
00:53:29.338 --> 00:53:31.507
<v Danny Palmer>That's part of my stag party. Yeah. Yeah.</v>

432
00:53:31.507 --> 00:53:33.018
<v Graham Cluley>Oh, that sounds brilliant.</v>

433
00:53:33.018 --> 00:53:33.579
<v Unknown>Yeah.</v>

434
00:53:33.579 --> 00:53:43.579
<v Danny Palmer>No, it was really good.</v>

435
00:53:43.579 --> 00:53:53.579
<v Danny Palmer>Really good fun. Yeah.</v>

436
00:53:53.579 --> 00:54:03.579
<v Danny Palmer>Well, it also reminds me of — it's not so much behind the scenes of scenes, but back when they had the 50th anniversary of Doctor Who, 13 years ago now, whatever it was, they had that drama, BBC drama about the making of Doctor Who.</v>

437
00:55:54.460 --> 00:56:04.588
<v Graham Cluley>An Adventure in Space and Time, I think it was called. Yes.</v>

438
00:56:04.588 --> 00:56:10.409
<v Danny Palmer>You mentioned the Cybermen with the cloth faces. Remembering that, I think it's based off of an old actual picture from the filming.</v>

439
00:56:10.409 --> 00:56:16.230
<v Danny Palmer>He's got a cigarette hanging out his mouth during a break in filming. But it's always good to see behind the scenes of how things are done, but maybe not so if those behind the scenes looks may or may not be true.</v>

440
00:56:16.230 --> 00:56:22.958
<v Graham Cluley>What's your pick of the week, Danny?</v>

441
00:56:22.958 --> 00:56:30.304
<v Danny Palmer>My pick of the week is not something very new at all. In fact, it's inspired by something which came out almost 30 years ago. First-person shooter Half-Life.</v>

442
00:56:30.304 --> 00:56:37.650
<v Danny Palmer>Half-Life is arguably the game that got me into PC gaming in the first place. So I've spent hours playing and replaying Half-Life and its expansions. For those who might be thinking, Danny, what are you rabbiting on about?</v>

443
00:56:37.650 --> 00:56:48.664
<v Graham Cluley>Yes.</v>

444
00:56:48.664 --> 00:56:54.297
<v Danny Palmer>In Half-Life, you are Gordon Freeman. You are an MIT-educated scientist employed at the Black Mesa Research Facility, which is a high-tech quantum physics and science lab.</v>

445
00:56:54.297 --> 00:56:59.929
<v Danny Palmer>An experiment basically goes wrong and it creates something called a resonance cascade, which floods the facility with aliens from another world.</v>

446
00:56:59.929 --> 00:57:15.996
<v Graham Cluley>And, oh, we've all had days like that, haven't we?</v>

447
00:57:15.996 --> 00:57:27.702
<v Danny Palmer>Yes. Anyway, this week I found myself with an urge to revisit Half-Life, but as you can imagine, as a game which first came out in 1998, looks a bit dated now.</v>

448
00:57:27.702 --> 00:57:39.407
<v Danny Palmer>This is where a game called Half-Life: Black Mesa comes in. It's a fan-made remake of Half-Life by a group called the Crowbar Collective, crowbar being sort of the iconic weapon of Gordon Freeman, which used the updated engine from Half-Life 2, which came along a few years later, and other later games from Valve that make it look more like a modern game.</v>

449
00:57:39.407 --> 00:57:53.014
<v Graham Cluley>Right.</v>

450
00:57:53.014 --> 00:57:58.409
<v Danny Palmer>And it's really, really good. I really enjoy it. And it's a fantastic way to revisit the world of Half-Life. It's an iconic game.</v>

451
00:57:58.409 --> 00:58:03.804
<v Danny Palmer>I found it when I was a teenager, when I was coming of age. And it's just been a lot, a lot of fun. And unlike a lot of games these days, you have to spend hundreds of hours to get to the end. You could probably finish this in about 14, 15 hours maybe.</v>

452
00:58:03.804 --> 00:58:17.777
<v Graham Cluley>Okay.</v>

453
00:58:17.777 --> 00:58:27.139
<v Danny Palmer>When you're not 14 and you're 40, you might not have as much time</v>

454
00:58:27.139 --> 00:58:36.503
<v Danny Palmer>to play these games.</v>

455
00:58:36.503 --> 00:58:43.186
<v Graham Cluley>Anyway, so Half-Life: Black Mesa, you can get it from Steam and</v>

456
00:58:43.186 --> 00:58:49.869
<v Graham Cluley>it only costs about £16.</v>

457
00:58:49.869 --> 00:58:56.059
<v Danny Palmer>Yeah, I would say, but Steam being Steam, it'll be in a sale at some point. You'll probably pick it up for a fiver if you wait a couple of months.</v>

458
00:58:56.059 --> 00:59:02.248
<v Danny Palmer>But that is my pick of the week.</v>

459
00:59:02.248 --> 00:59:11.746
<v Graham Cluley>Well, that just about wraps up the show for this week. Thank you so much, Danny, for joining us. Where can folks follow you online and find out what you're up to?</v>

460
00:59:11.746 --> 00:59:16.958
<v Danny Palmer>Well, I'm a freelance writer, journalist, et cetera. But no, my LinkedIn is probably the best place to keep up with me. I'm pretty active on Bluesky. Trying to get back into Mastodon as well. Keep sort of kind of forgetting it's there.</v>

461
00:59:16.958 --> 00:59:25.893
<v Graham Cluley>And you can find me, Graham Cluley, on LinkedIn, or you can follow Smashing Security on Bluesky, Reddit, and Mastodon and all those sort of places. I'll be lurking up there too. And don't forget to ensure you never miss another episode. Follow Smashing Security in your favourite podcast app such as Apple Podcasts, Spotify, and Pocket Casts.</v>

462
00:59:25.893 --> 00:59:34.829
<v Graham Cluley>For episode show notes, sponsorship info, guest lists, and the entire back catalogue of 479 episodes, check out smashingsecurity.com. Until next time, cheerio. Bye-bye.</v>

463
00:59:34.829 --> 00:59:48.434
<v Danny Palmer>Bye everyone.</v>

464
00:59:48.434 --> 00:59:48.846
<v Graham Cluley>You've been listening to Smashing Security with me, Graham Cluley, and I'm ever so grateful to Danny Palmer for joining us again this week. Thank you, Danny. And to this episode's sponsors, Arctic Wolf, NordLayer, and Vanta. Now, we all know what's coming up. It's the bit where I pull out names at random from the hat of Smashing Security Plus supporters over on Patreon. And you know what? I think this week I'm going to dig deep into the bottom of that. I'm going to pull out some of the very longest-serving supporters of the show. Some of these fine fellows have been supporting the show for, oh, I don't know, six years or more maybe. So who have we got? Thanks to Dimitri. That name always arrives with a certain brooding intensity. Richard van Liesen, who I imagine owns a fine art gallery in the Netherlands. Huge thanks to Dr_Herbalist, who always has his prescription pad open, has terrible handwriting, but knows where his Shift key is. Scotia, and also the gloriously monikered Jonathan Haddock, who I think I met once. Who else? Well, cheers to Lisa with an S and Jane with a Y, and also to the Scrabble master Robert Ødegard. He's got vowels going in all directions. And finally for this week, big love to Just Nate Please, Roy Tate, and Yuri Taraday, rounding things off in magnificent style. You know what, guys? I love you all. Thank you so much for supporting the show. It means so much to me and it encourages me to make the podcast every week, so thank you for all of your support. If you would like to be like them, you don't only get the chance for me to make fun of your name and thank you at the end of the show; you also get the episodes ad-free, ooh, and you get them earlier than the general public. So that's pretty neat, isn't it? If you'd like to join up, just head over to smashingsecurity.com/plus for all of the details. You can also support the show in other ways. You can like, you can subscribe, you can leave a 5-star review. Let me say that again. You can leave a 5-star review. Go on, leave a 5-star review wherever you listen, or simply spread the word. Every little bit helps. It makes all the effort worthwhile. And until next week, cheerio. Bye-bye.</v>
