This job interview could destroy your company • Graham Cluley

This job interview could destroy your company • Graham Cluley

GRAHAM CLULEY

I was in a car park and I found my car, at least what I thought was my car. And I thought, why isn’t my key working? And I tried the door and it was only unlocked.

Only when I saw how clean the car was that I realised it couldn’t possibly be mine.

PAUL DUCKLIN

You looked in the back and there were no food wrappers and discarded cardboard boxes from three months ago.

Unknown

How dare you! I don’t know if I’m getting a little bit old.

Smashing Security, Episode 478: This Job Interview Could Destroy Your Company, with Graham Cluley and special guest Paul Ducklin.

Hello, hello, and welcome to Smashing Security, Episode 478. My name’s Graham Cluley.

PAUL DUCKLIN

And my name is Paul Ducklin.

GRAHAM CLULEY

Duck, welcome back to the show.

PAUL DUCKLIN

Thank you very much, Graham. Pleasure to be back.

GRAHAM CLULEY

There’s been big news actually on the cybersecurity front since our last episode.

PAUL DUCKLIN

I can’t think what you’re talking about, Graham. What could it be?

GRAHAM CLULEY

Unfortunately, due to the schedule of Smashing Security, we recorded last week’s episode just before the whole OpenAI going rogue, attacking Hugging Face story, which made a thousand headlines.

PAUL DUCKLIN

Now you know how Microsoft feels when Nightmare Eclipse Smashing Security publishes an exploit minutes after Patch Tuesday’s dropped.

GRAHAM CLULEY

We’re not going to talk about this very much because frankly, everyone else has spoken about it. I’ve blogged about it. It feels like old hat by the time this episode comes out.

But people are asking, is this the end of the world as we know it? But some people have also thought that maybe there’s a bit of hype around this.

Maybe it’s working to the advantage of the AI company’s PR machine. Have you seen anything like that?

PAUL DUCKLIN

We do seem to have had that quite a few times recently with these AI companies, haven’t we?

Wasn’t it Anthropic that said, oh, we’ve got this product, it’s so dangerous, we can’t release it.

And then when the government turned around in the US and said, okay, we are going to regulate it, it’s like, what? You’re going to regulate it? But we’re libertarians.

If there’s any regulation to be done, we’ll do it. How dare you? You said, well, you spent ages hyping up how dangerous it was because it’s so clever. You can’t have it both ways.

But you’re right, Graham, I think. There have been at least a few people who have been somewhat cynical about this.

So may I read you a post that I saw from a chap in Cambridge, UK, by the name of Graham Bell.

Now, I don’t necessarily agree with all of this, just to make it clear, but by golly, I laughed so hard.

PAUL DUCKLIN

And here is what he wrote, Graham.

So it turns out that if you train an AI model on hacking and then you train it on sci-fi stories about AIs being total dicks, and then you set it loose in a fairly secure sandpit with safety and sanity settings deliberately set to zero, it runs off to hack your biggest competitors and acts like a total dick.

Who could possibly have guessed that might happen exactly in time to fit in with the week’s political PR campaign about the competition posed by Chinese and non-US AI models?

What are the odds of that?

GRAHAM CLULEY

Well, it’s an excellent question.

PAUL DUCKLIN

It did make me laugh.

GRAHAM CLULEY

Before we kick off, let’s thank this week’s wonderful sponsors, Arctic Wolf, NordLayer, and Vanta. We’ll be hearing more about them later on in the podcast.

This week on Smashing Security. We won’t be talking about how spies hid malware commands inside Microsoft 365 calendar meetings scheduled for the year 2050.

You’ll hear no discussion of how a ransomware gang called The Gentlemen is holding a famous Dutch ice skating rink hostage.

And we won’t even mention how a flaw in Shark robot vacuums lets attackers remotely access your camera, steal your Wi-Fi password, and download a map of your home.

So, Duck, what are you going to be talking about this week?

PAUL DUCKLIN

I’m going to be asking two questions, Graham. Firstly, how safe is your car alarm? But more importantly, how do you know if you’ve even got one?

GRAHAM CLULEY

Normally it goes off at 2 o’clock in the morning. That’s how I know if I’ve got a car alarm.

PAUL DUCKLIN

Yes, and you find out because your neighbours have put a brick through your windscreen the next morning.

GRAHAM CLULEY

And I’ll be asking, could a fake job interview drain your bank account and fund a nuclear weapons programme? All this and much more coming up on this episode of Smashing Security.

JOE

Graham, am I right in thinking that Arctic Wolf are sponsoring the show this week?

GRAHAM CLULEY

You are right, Joe.

They’ve just published a new report, 2026 State of the Cybersecurity Attack Surface, and they analysed over 800,000 real IT assets to find out how exposed organisations actually are.

JOE

And I’m guessing everything is hunky-dory?

GRAHAM CLULEY

Not so much. The reality is they found 1 in 3 IT assets is missing at least one critical security control.

JOE

1 in 3? That’s terrible.

GRAHAM CLULEY

Isn’t it just? 10% of assets have no endpoint security at all. 17% are completely invisible to the tools that are supposed to be monitoring them.

JOE

So the tools don’t even know those assets exist?

GRAHAM CLULEY

Right. Ghost assets wandering around your network, unprotected, unmonitored.

JOE

Like a retired geography teacher who’s somehow still on the school network.

Nobody added him, nobody removed him, and he’s been quietly in there for 11 years downloading maps of Paraguay.

GRAHAM CLULEY

Yeah, I guess so, Joe. The point is, your attackers will find him before you do because they are specifically looking for the forgotten, the unpatched, the invisible.

That’s the path of least resistance.

JOE

So what does the report tell us to actually do about it?

GRAHAM CLULEY

Arctic Wolf’s report covers how to prioritise the exposures that actually matter, cut through all that noise and verify that when you fix something, it actually stays fixed.

And the report is free to download.

JOE

Free. I like that. Where do I get it?

GRAHAM CLULEY

SmashingSecurity.com/ArcticWolf.

JOE

That’s SmashingSecurity.com/ArcticWolf. And thanks to Arctic Wolf for supporting the show.

GRAHAM CLULEY

So, chums, Duck. How would you like to be headhunted? Would you like to be headhunted, Duck? Well, ducks have suffered from being hunted in the past.

PAUL DUCKLIN

Yeah, my totem. Don’t tell me. There’s even a thing called a duck gun, which is a shotgun so big that they were literally used to shoot dozens of ducks at the same time. Very ghastly.

So I don’t think I’d like to be duck hunted.

As for being headhunted, that’s always struck me as a rather worrying metaphor, Graham, because it sounds as though the other person’s going to get rather more out of it than you do.

GRAHAM CLULEY

Yes, maybe they’re not interested in the rest of you. Well, it means you could end up with a dream job though, a great salary, fabulous workmates.

You know, you could be going into a booming industry. All you’ve got to do often these days is complete a short online assessment of your skills.

If someone was approaching you, maybe they’d put out their little feelers on LinkedIn or whatever and say, “Duck, we’ve decided you’re the man for us, come and apply for a job.” It seems fair enough doing an online assessment, doesn’t it?

I mean, recruiters are asking you to do those all the time, I suspect. This is something which is maybe working in a similar field to which you’re already working.

Maybe, for instance, you work in cryptocurrency.

GRAHAM CLULEY

All they’re asking you to do on this occasion is they’re saying, look, answer a few multiple choice questions.

Maybe turn your webcam on because they want to make sure that you’re not cheating.

They don’t want you to be one of those North Korean people who’s deepfaking, trying to get a job inside your company. So it’s perfectly normal stuff.

So in this case, the company recruiting you doesn’t exist. Surprise, surprise, because you’re listening to Smashing Security.

Sitting at the other end of this fake job interview is someone from North Korea.

And I’ve already alluded to these, all these stories we’ve seen in recent years of Western companies unwittingly hiring North Korean IT workers and giving them remote access to their computer systems.

And they do this to plant malware or ransomware or steal intellectual property. Cause all kinds of mayhem.

PAUL DUCKLIN

Or just to draw salaries, right? Sometimes for years and years at a time.

GRAHAM CLULEY

Why not? I mean, these people could be employed by half a dozen different companies, you know, and they could be using AI to actually do the work for them as well.

PAUL DUCKLIN

Surely not, Graham.

GRAHAM CLULEY

And of course, maybe you’ve shipped them laptops, you’ve given them all kinds of goodies.

PAUL DUCKLIN

Yes, because that’s part of the trick, isn’t it? The laptop goes to somebody in the US who runs it.

GRAHAM CLULEY

Yes. There have been people who are American citizens who’ve actually been arrested in those cases. Anyway, this isn’t about that, Duck.

This isn’t about fake North Korean job applicants. At this point, you are applying for a job, or rather a nonexistent job.

And this is what some researchers are calling the ClickFake interview attack.

And the boffins at security firm SOCRadar, they’ve published a detailed breakdown of an attack being carried out by a North Korean hacking group called Famous Chollima, also known rather less glamorously as Wage Mole.

And this isn’t just some tinpot hacking group looking to make a quick buck. This is North Korean financially motivated cyberattack.

This is their attempt to get round international sanctions. Early on, this group, Chollima, they were targeting bank transfer systems, ATMs.

We’ve all heard of the Lazarus Heist, for instance. And now they’re focused in almost entirely on cryptocurrency. That’s where they’re getting their spondules.

And according to researchers, North Korean-linked hackers have stolen approximately $643 million worth of cryptocurrency in the first 6 months of this year alone.

So over half a billion dollars of cryptocurrency has allegedly been stolen by North Korean hackers in 6 months. It’s a huge amount of dosh.

PAUL DUCKLIN

And that’s good luck getting your money back, right? So that’s why they’re doing it that way, I suppose.

GRAHAM CLULEY

Yeah, even if you do manage to trace it, what are your chances of getting the cash back? And that money is funding North Korea’s missile and nuclear ambitions.

So there’s some real geopolitical consequences of hacks like these. And I guess one of my questions for you, Duck, is do you think people are taking this seriously enough?

I mean, you hear stories, you think, oh, you know, it’s just another state-sponsored hack.

But when it’s actually funding that kind of thing, do you think countries are taking enough action?

PAUL DUCKLIN

I sometimes find myself, to be honest, feeling a little bit cynical about the extent to which cybersecurity companies that, let’s be fair, some of them do trade on fear, uncertainty, and doubt, want to talk up the whole state-sponsored actor thing.

And the reason I don’t like that is if this weren’t North Korea, if this were just 17 or 19-year-old kids, say, in the UK, who are now heading off to prison, who’d taken out Transport for London for several weeks.

PAUL DUCKLIN

Would that make it less damaging to society as a whole?

So I think that all of this matters, even if no ransoms are paid, even if people don’t take the job, even if it’s not about trying to steal intellectual property.

I think the problem is that it’s almost as though we don’t take the minor ones seriously enough.

Because there’s this big, bad, ugly North Korea ransomware-will-get-money-despite-sanctions thing.

Whereas in fact, you know, you look at the Jaguar Land Rover hack in the UK last year — apparently that affected the UK GDP by something like 0.2 percentage points.

GRAHAM CLULEY

It’s amazing, isn’t it?

PAUL DUCKLIN

That’s how significant it was. And they didn’t even make any money out of it, the crooks.

PAUL DUCKLIN

All this, whether it’s cybercrime or state-sponsored actors, we absolutely do need to take it seriously. And there’s nothing that does not deserve our attention.

GRAHAM CLULEY

So let’s get into the weeds of how this fake interview hack actually works.

So Famous Chollima, this hacking group, they either create an entirely fake business, an entirely fake company, which is trying to hire you for a job, or they impersonate a real one in the cryptocurrency sector.

PAUL DUCKLIN

And those companies come and go very regularly.

PAUL DUCKLIN

And if it’s a startup, you wouldn’t expect the company to have a massive history anyway, would you?

GRAHAM CLULEY

So they set up convincing-looking websites. They use typosquatted domains if they want to pretend to be a company which has already existed for a while.

And then they go looking for potential targets on LinkedIn. Of course, that’s where the criminals love to find you and find out all about you.

They identify people working in that industry, and they’re specifically targeting non-technical people, so they’re not necessarily going for developers — they might be going for people in your legal department, people who work in compliance, people who work in finance and the like.

And these are people inside a company who may have access to company funds or may know people who do.

So it’s a good sort of launching pad for a further attack inside a company if someone manages to steal your credentials.

PAUL DUCKLIN

It’s almost better than a developer, isn’t it? Because you’ve not just got the people who might publish code in the future.

You’ve got the people who can authorise funds transfer tomorrow.

GRAHAM CLULEY

Yes, exactly. And the hackers, they’re posing as recruiters. They pitch a lucrative new role. They say, oh, Duck, you know, you seem very interesting to us. Here’s a link.

PAUL DUCKLIN

Oh, thank you, Graham.

GRAHAM CLULEY

If you want.

PAUL DUCKLIN

Well, it is quite attractive, isn’t it? If somebody seems to have noticed you — yeah, you’re a great guy and we’ve noticed you.

PAUL DUCKLIN

I’d take a second look, I think.

GRAHAM CLULEY

So this isn’t amateur hour by any extent. These fake assessments, these online tests which they’re doing, they’re really convincing. They look professional.

They’ve got the company’s branding. They’re very slick. They ask you, of course, to fill in your details.

So you’re entering your name, your email, your LinkedIn URL, your phone number, your work experience. All of this, by the way, has been handed directly to the attackers.

No wonder whether that in itself could be of advantage to these hackers, maybe in future campaigns as well.

PAUL DUCKLIN

Absolutely.

Even if you bail out at that point, if they’ve got name, email address, phone number, home address, that’s as bad as data breaches that we get concerned about from companies that sell stuff online, isn’t it?

GRAHAM CLULEY

Anyway, the online assessment continues and you’re being given multiple choice questions tailored to the job you’re asking for.

PAUL DUCKLIN

So these are genuine looking questions. It’s not like nonsense.

GRAHAM CLULEY

Oh no, no, it’s not nonsense. They’re not asking you what your favourite crisp flavour is or something like that, you know, salt and vinegar or cheese and onion.

PAUL DUCKLIN

So they probably just copied this from a legit job application questionnaire.

GRAHAM CLULEY

Or they went to an AI and said, what would be good multiple choice questions to ask someone who is a compliance officer or inside a cryptocurrency company?

And each section of these multiple choices has a countdown timer, so it’s ticking away — you can see it ticking down.

And if you run out of time, the form auto-submits, so you are up against the clock. And of course you’re feeling pressure because you’ve been offered this fantastic job.

PAUL DUCKLIN

I must get to the end. I don’t want them to learn too little about me.

PAUL DUCKLIN

So it’s like a game show.

GRAHAM CLULEY

It is. There should be music. It should be like Jeopardy going doo doo doo doo doo doo doo.

PAUL DUCKLIN

I was thinking more of Countdown.

GRAHAM CLULEY

Oh, Countdown. Yes. Sorry, I should have kept it British. And also, if you try and switch tabs, you suddenly get this warning pop-up saying, whoa, whoa, whoa, what are you doing?

The hiring team might be monitoring your session, so stay focused, it says.

So it’s very stressful — you think you are being tested under a proper job application scenario, really.

PAUL DUCKLIN

Well, it’s a proper scenario, it’s just not a real job.

GRAHAM CLULEY

And by the time you reach the end of the online assessment, you’ve been complying with this platform’s instructions for around about 20 minutes. You’re probably sweating like a pig.

PAUL DUCKLIN

Oh, so they don’t mess around.

GRAHAM CLULEY

Oh no, no, no, this is the real thing. And of course, the longer you take the test, the more you believe it’s real.

Whereas if they’d only asked you 3 questions and then said, give us your bank account details, you’d be suspicious.

PAUL DUCKLIN

This is fascinating, Graham, because they’ve turned the way that these sort of scams used to work on their head, haven’t they?

It used to be, hey, do you want to only have to work 2 hours a week from home and make a living wage? And we don’t need to know a lot about you — just do you have a bank account?

Now they’ve kind of flipped that around because everyone’s going, well, that’s too easy.

And there have been cases of people who’ve taken those jobs themselves going to prison for basically aiding and abetting money laundering.

So they’ve made this look even more legit than usual by actually making it hard.

GRAHAM CLULEY

That’s right. And so at the end of these 20 minutes, you are 100% in interview mode, right? They say they want one more thing from you.

They say, we want you to record a short video of yourself answering a question. We want to be sure you’re not a bot. But then the interface says, oh, something’s not working.

It says your webcam is freezing, but don’t worry. And inside this beautiful interface, there’s a little “here’s how to fix the problem” link.

And you go there and there’s some very friendly advice lovingly arranged for you.

PAUL DUCKLIN

Which is exactly what legitimate WebRTC services do.

GRAHAM CLULEY

That’s right. The super friendly troubleshooting instructions tell you that all you need to do is either press a sequence of keys to initiate the graphics driver update.

PAUL DUCKLIN

Let me guess that one of them is Windows R?

GRAHAM CLULEY

That’s right. Or if you’re wise to that, which is of course a click-fix attack, isn’t it?

PAUL DUCKLIN

Where it— yes, because it runs the command window where anything you type in, you are running a command on your computer so it can do anything it wants.

GRAHAM CLULEY

That’s right. So it pastes something from your clipboard into your terminal screen, the Run command, in order to download a piece of malicious code.

Or of course, if you’re a bit suspicious of that for any reason, if you are a bit wise to that kind of thing, which probably most non-technical people aren’t wise to, the kind of people who they’re targeting.

PAUL DUCKLIN

Those click-fix attacks in general still work very well, judging by how many reports we get of people with things ending badly, usually losing money from their bank account.

GRAHAM CLULEY

So the other thing they do is they list in the instructions the URLs where you can download the updated driver from.

So they say you can get the latest version of the webcam driver from Microsoft’s website at this address.

PAUL DUCKLIN

And let me guess, the text is not what you get when you click the link.

GRAHAM CLULEY

So if you try and copy and paste that link from the web interface, what actually gets copied into your clipboard is something else.

And that command, which you then paste in at the command prompt, does do a little bit of jiggery-pokery.

So it echoes the command which you thought you were going to be doing to download it from Microsoft.com. But it actually is downloading from another site entirely.

It does something very similar, by the way, on Mac, although it doesn’t do it via Microsoft.com.

And so you end up with a malicious download which has just been run, which you have given permission to run on your computer, and you are super keen for it to happen.

And even when on your Mac it pops up.

PAUL DUCKLIN

Do you think even though this might be considered slightly risky, like how harmful can it be to download something from Microsoft and run it, because isn’t that what you do every Patch Tuesday anyway?

GRAHAM CLULEY

Exactly. Exactly. So this is a variant of those click-fix campaigns we’ve talked about in the past, but it’s been woven into this new fake interview social engineering technique.

Now, why do they succeed so well, do you think, Doug? It sounds like something which should be obvious, isn’t it? But clearly lots of people are continuing to fall for these.

PAUL DUCKLIN

I think it’s probably for the same reason that something like this works, for people who wouldn’t fall for the “hey, you don’t even need to have an interview for this job” because you’ve taken existing attacks and flipped them around.

So I think the background to that whole ClickFix thing where it says you don’t need to call this 1-800 number, which everyone knows is a scam, right? It’s automatic.

It says, “No, you can fix this yourself.” And you think, “Great, I never had to talk to anybody.” You know, it feels sufficiently different from the way you’ve learned attacks work that you go, “How could I have put myself in harm’s way?” In exactly the same way, when everyone learned don’t click links in emails, the crooks would send a PDF and then you open the PDF and then they’d say click a link in the PDF and people would go, “Ah, it’s not an email,” but it’s the same link.

And so they’d feel comforted. I guess that’s it. It’s just sufficiently different.

GRAHAM CLULEY

And in this particular case, after you’ve spent 20 minutes trying to get the job of your dreams and you’re already flustered because of the countdown and everything else, and you just want to fix your bloody webcam and get the interview done so you can apply for the job.

PAUL DUCKLIN

Yes, because imagine if you have to start this whole thing all over again from the top.

GRAHAM CLULEY

So on Windows, you end up with a remote access Trojan called PyLangGhost, which is written in Python.

If you’re on a Mac, it’s GoLangGhost, which is a remote access Trojan written in Go.

PAUL DUCKLIN

Those names must have taken them months to think up.

GRAHAM CLULEY

These pieces of malware give the attackers a full remote shell to your computer, through which they can upload and download files, go through your crypto wallet, steal your passwords.

In fact, they specifically target, I think it’s around about 30 different browser extensions for different cryptocurrency wallets.

If you are using a browser extension for your cryptocurrency wallet, can I gently suggest to you that you don’t use a browser extension for your cryptocurrency wallet?

PAUL DUCKLIN

I think you could probably extend that to things like built-in browser password managers as well. Yes.

GRAHAM CLULEY

And all the time you’re going through this process, bad news, they really were recording video of you.

So now potentially you could become a North Korean deepfake in a future attack as well.

PAUL DUCKLIN

And the thing to remember about this is that wherever you bail out in this, after about the first 30 seconds, they still get some or all important stuff about you up to and including a video of you being your very, very best and most realistic self with your real voice.

GRAHAM CLULEY

Absolutely.

So what we’re seeing now are North Korean hackers — they aren’t just targeting developers working in the cryptocurrency world, they’re attacking all kinds of non-technical people too.

Legal professionals, finance staff who might be using LinkedIn every day, might be receiving regular messages from recruiters, and they won’t necessarily see the instructions on how to update their webcam driver as a red flag, which it most certainly is.

I know lots of people are after a better job, but boy, you’ve got to be really careful because this scam, I think, would trick many, many people.

Right, before we crack on any further, Jo and I want to take a moment to tell you about one of today’s sponsors, Vanta.

JOE

We’ve got a question for you. What’s the thing that keeps you staring at the ceiling at 2 AM when it comes to your company’s security?

GRAHAM CLULEY

Is it wondering whether you’ve actually got the right controls in place? Whether one of your suppliers has been quietly compromised? Or is it the truly soul-destroying one?

Why on earth are we still running our entire security programme out of a spreadsheet?

JOE

If any of that hit a little too close to home, that’s where Vanta comes in.

Vanta takes all that tedious manual security grind, chasing down evidence, wrestling with questionnaires, updating the same cells for the thousandth time, and automates the whole thing.

GRAHAM CLULEY

Their trust management platform keeps a continuous eye on your systems. It pulls everything into one central place and keeps your security program audit-ready around the clock.

Yes, it uses AI, but the genuinely useful kind — flagging risks, streamlining evidence collection, and slotting into the tools your team already relies on.

The upshot of this is you move faster, scale without the usual headaches, and maybe, just maybe, actually get a decent night’s sleep.

JOE

Sounds lush. Find out more and get started at vanta.com/smashing.

GRAHAM CLULEY

That’s vanta.com/smashing. And a big thank you to Vanta for supporting the show. Duck, what’s your story for us this week?

PAUL DUCKLIN

My story is about a technical paper where the overview has been released by the University of California in San Diego. So we know what it’s about.

Sadly, though, they’re promoting the paper which will only be delivered at DEF CON and then shortly afterwards at USENIX. So we don’t have the full paper.

PAUL DUCKLIN

But we certainly have enough to go on. And it deals with car alarms.

PAUL DUCKLIN

Now, you said at the top of the show, you know when someone’s got a car alarm because it goes off at 2 o’clock in the morning. But what if you don’t know you have a car alarm?

PAUL DUCKLIN

And this is a fascinating story of how the fact that something was not terribly obvious and not seen as particularly risky because it wasn’t in everybody’s face led to a bug that was undiscovered for years and years and years, that actually could put a lot of vehicle owners in harm’s way.

And the backstory to this is very interesting, and it goes back to the wireless security research department at UCSD, as far as I can make out.

The professor who supervises that had a student who in 2018 decided, hey, I’m going to look at Bluetooth skimmers. Do you remember skimmers, Graham?

PAUL DUCKLIN

You know, before cards went to chips in America, which was one of the last countries where this happened, and because they have a propensity that when you go to a fuel station, a gas station, a petrol station and fill up, you swipe your card at the bowser, so you pay in advance.

It was a great place for a crook to insert one of those skimmers which reads the mag stripe.

That leads to the problem: how does the crook get the data back out of the petrol pump after the attack?

And so the first ones, they had to sneak in under cover of darkness or under an umbrella or something and retrieve an SD card and plug in a new one.

And then they figured, why don’t we just use wireless, or even more easily Bluetooth?

And then all we do is we just drive by all the gas stations where we’ve got our skimmers installed every night and collect the day’s data.

PAUL DUCKLIN

So this guy figured, hey, I want to go and sit around at gas stations, with permission of course, and record the Bluetooth transmissions and see what these skimmers look like.

Can we work out something about the malware from them? Can we write a thing that will detect that the skimmer’s there, etc., etc., etc.?

So he did write that paper, and that all went very well. But in amongst all of that, you imagine at a fuel station there’s going to be a lot of Bluetooth chat going on.

Even back then, most cars had Bluetooth pairing and stuff inside the car that would talk Bluetooth all the time.

PAUL DUCKLIN

So obviously the first thing you have to do when you want to focus on malware that’s mixed in amongst with good stuff is filter out all the good stuff.

And it turns out that they found during this research that there were a load of Bluetooth packets that looked legit, but that they couldn’t tie back to a particular automotive vendor.

So they weren’t quite sure what it was.

But the guy doing the research, apparently he noticed that if he scanned Bluetooth while he was, say, driving on the freeway, he got this same sort of traffic.

So the inference is, even though they don’t know quite where it’s coming from, it’s associated with the vehicles, not with the fuel pumps.

GRAHAM CLULEY

So — and not with a particular brand of vehicle, because you could look to see what was on the forecourt.

PAUL DUCKLIN

Normally the Bluetooth device, it’s got a MAC address or whatever that says this is, yeah, you know, Honda or this is Toyota or this is General Motors or this is Jeep or whatever it is.

This was something that they weren’t sure about, but it clearly went with the vehicle. So they figured, well, it’s not important for the skimming research, right?

So they were able to remove it, focus on the skimming stuff. Great.

So 6 years later, 2024, someone else came along and said, oh, I’m looking for a summer project, to the same prof, and said, I want to maybe do some wireless stuff.

And the prof said, hey, we had this interesting thing 6 years ago, but we had all this data. It wasn’t card skimming, it was automotive, but it wasn’t important to that research.

They’ve got all these things that we don’t quite understand. Why don’t you go back and see what this is all about?

PAUL DUCKLIN

So a team of researchers got together and they did exactly that. And they traced it back to KARR Car Alarms.

And it was actually a car alarm company based out of Irvine, California, the greater LA area.

And their peak market was in southwestern California, which is why in San Diego they were seeing so many of these things. And it turned out that this was an aftermarket car alarm.

You think in the modern era, why do you need an aftermarket car alarm? I mean, the car’s secured by the automotive manufacturer. Why do you need an extra one?

And the answer is that this is a product that was really targeted at car dealers, people who had vehicle lots where they might have 100 or 200 cars on the lot.

PAUL DUCKLIN

And the idea was they’d install this aftermarket alarm that let them control the cars as well as the stuff that was already put in by the automotive vendor.

Quite a good idea, right? It means that you cut across all the vendors, you can lock up all your cars on the lot, maybe you get better insurance.

And so you’re putting this thing in before the car’s sold.

You’re not putting it in for the car owner, you’re putting it in so that at night you can just buzz around the lot with a Bluetooth sender and just lock all your cars or have them lock automatically.

GRAHAM CLULEY

Oh, okay, that makes — yeah, rather than having all kinds of different devices and all kinds of different fobs for every car.

PAUL DUCKLIN

And then when a customer says, oh, I want to test drive that Lexus, or I want to test drive that Jeep Cherokee or whatever, then they hand the customer the keys that would open and start the car.

And if the customer then opens the car, jumps in, tries to drive off, it won’t work.

In other words, you can do your final check and then you can unlock the car on the lot with a special app.

And they also had an extra version which could geofence, limit how far the person could drive.

So if they tried to drive too far on the test drive — and also it’s an alarm that has an alarm — it’s plumbed into the vehicle itself so it can lock and unlock, and it can also do an additional layer of immobilisation.

It’s quite a great idea for a dealer to have this.

GRAHAM CLULEY

Okay, so it’s not like having two padlocks, as it were, on a car. It’s a lock which will completely unlock the car, even if the other lock is locked.

PAUL DUCKLIN

I’m not sure about this, because the full paper hasn’t come out. I suspect that what they do is they plumb it into the system so they take control of lock and unlock.

PAUL DUCKLIN

So that sort of overrides the lock of the fob.

Which is great, because it means that if someone breaks into the office and steals all the car keys, they can’t go around unlocking the cars and driving off, because they’re kind of independently locked.

It turns out that this particular system had a rather unfortunate bug.

And I’m sure you can guess what’s coming next, Graham, if you think of the biggest cryptographic blunder you could possibly make in a security application, viz, one password to rule them all.

GRAHAM CLULEY

Oh, well, hang on. You’ve said this has been a problem since, what was it, 2017, 2018 or something?

PAUL DUCKLIN

2018 is when those researchers first noticed this traffic. And apparently this product range came on the market in 2017.

So yes, this has been an issue, but nobody thought to look until 2024. For all those years.

GRAHAM CLULEY

So for nearly 10 years, they’ve all been effectively locked with the same master key.

GRAHAM CLULEY

All these vehicles.

PAUL DUCKLIN

So if you — you sound surprised as though this sort of mistake would never be made in computer science, Graham.

GRAHAM CLULEY

But hang on, hang on. It seems strange that it hasn’t been spotted because imagine you were at a mall, for instance.

So you’ve bought your lovely car from the lovely dealer and it has one of these — it’s car with a K, isn’t it? K and a double R. K-A-R-R.

So I almost want to be piratical and go Karrrr or something like that just so we can differentiate between the two.

PAUL DUCKLIN

Oh, well done. I never thought of that. I wish I’d thought of that because then I could have done it.

PAUL DUCKLIN

Karrrr. Karrrr.

GRAHAM CLULEY

So you’ve got this Karrrr thing protecting your car, as we’ll call it, or the vehicle.

If you were at the mall — I mean, I’ve been in malls before where I haven’t been quite sure where my car is.

And so I might press the button a little bit earlier in the hope that the lights will flash. Just for the blip.

PAUL DUCKLIN

And then it’s echoing and you think, oh, I can’t find it. So you look for the light. Yes.

GRAHAM CLULEY

But wouldn’t people be accidentally unlocking the wrong car?

And wouldn’t people then be saying, you’ll never guess what happened to me the other day — I went down to the shopping centre and my car was unlocked unexpectedly, or I unlocked someone else’s car.

So how was this not spotted for like 10 years?

PAUL DUCKLIN

Yes, I wondered that.

Apparently they found in the end about 2.2 million of these cars currently floating around in the US, of cars, a million of them in the Southwest Californian area.

So you’d think, as you say, yeah, it would have happened to someone. So you’d never guess what happened.

Or if you had bought two cars, if you were a family with more than one car and you’d bought them from the local dealer buying a bunch of cars at the time, I’m assuming this because obviously the paper hasn’t come out, but it’s one thing for the app to authenticate with the device in the car, right?

It’s another thing for it to unlock that particular car because I’m guessing that the app, as you have it on your phone, it has the key that lets it into everybody’s device, and then if you like, as a secondary factor, it has what, let’s call it a username or a unique ID for that car.

So imagine if you’re the legit app, you break into the system, but you don’t do any kind of exploit. You just say, hello, are you car XYZ? And the car goes, no.

And so the legit app probably goes, okay, nothing to do. So it only unlocks when it finds that it’s at the right car. Ah, I got you.

So unless you went in and found out that the authentication actually did packet capture and looked in and did some reverse engineering and figured that there’s sort of authentication followed by identification, you might never know that the authentication worked for everybody.

Of course, this was what the researchers were looking for, and they found that they could create their own version of this app that authenticated to any device.

PAUL DUCKLIN

In fact, as far as I know, it can enumerate all the vehicles within immediate radius, or you can walk around and it captures all the usernames, if you like, for the vehicles by authenticating one after the other.

And then you can pick which one you want to use in their fake app.

And then their app identifies itself like the legit app saying, “Are you Car X?” And Car X goes, “Yes, here I am.” And then they can set off its horn, its hooter, they can unlock or lock it.

If it’s not already running, there’s even apparently for safety, there’s an immobilise.

So if you’re a really nasty piece of work, you could wait until someone was getting into their car and then they take the real car key and they put it in the little slot or into the ignition if it’s still one of those.

And then just before they start the motor, they immobilise it.

Now that person’s in the car, door open, can’t go anywhere, car’s unlocked, and now creepy person has stopped them driving off.

GRAHAM CLULEY

Yeah, that’s scary.

PAUL DUCKLIN

There are all sorts of bad things. So my first thought was somebody would have spotted this.

If every car key was the same in the old days of physical keys, you’d notice that pretty quickly because occasionally you go to the wrong car, don’t you?

Because they all look the same.

GRAHAM CLULEY

I, the other day, tried to get into the wrong car. I was at a car park. And I don’t know if I’m getting a little bit old.

I was in a car park and I found my car, or at least what I thought was my car. And I thought, why isn’t my key working?

And I tried the door and it was only when I saw how clean the car was that I realised it couldn’t possibly be mine.

PAUL DUCKLIN

You looked in the back and there were no food wrappers and discarded cardboard boxes from 3 weeks ago.

GRAHAM CLULEY

How dare you. How dare you?

GRAHAM CLULEY

How dare you?

PAUL DUCKLIN

Very easily, Graham.

PAUL DUCKLIN

So there’s a catch to this that these researchers discovered, and that is that presumably because it’s quite complicated to install this device, and apparently Carr has employed something like 250 people to travel around, particularly in southwestern California, to travel around to lots to do the installation, to do it professionally and neatly and everything.

Because it does involve sort of integrating this device with at least part of the car’s regular system, so it’s not a trivial matter to uninstall them.

PAUL DUCKLIN

So guess what the solution to that problem was in the cloud era, Graham?

Well, what the dealer can do, and this is pitched by Carr on their website as a potential feature, is to say, well, you’ve bought the device, you put it in the car, just leave it there and say to the customer, would you like the add-on extra alarm immobiliser super security feature?

And you offer to sell it to them.

And if they go, hey, it’s already installed, it’s professionally installed, if I want an aftermarket alarm, I don’t have to go with my brand new pride and joy and have someone else drilling and cutting and hacking and wiring in it — it’s professionally installed.

They have a look, they go, well, that looks very… yeah, I’ll take it. How much is a subscription? You wrap it into the lease or whatever. All good.

And if they say, nah, I don’t really want it, you just go, okay, cut your losses. Yeah, it’s not the device that makes the money, it’s the subscription.

And I don’t know how they work this out, but UCSD’s guess is that half of those 2.2 million vehicles wandering around the US with this device in have one that’s in there and deactivated.

Well, do you want to hear the interesting extra part of this bug?

GRAHAM CLULEY

Oh no, no, no.

PAUL DUCKLIN

It’s basically the customer account that’s deactivated, not the device. And the device still carries on doing its Bluetooth chattery whenever the car’s on.

So you can, if you know the magic identifier, you can still track it, even though you said, I do not want the device.

Because you do not want the device, you don’t have a cloud account, you don’t have the app, you’re not going to get the, hey, there’s this urgent update you need to apply.

You’re not even going to know that you’ve got the device in the car. What these researchers found is that there is — don’t laugh, Graham.

I did it then, but I’m not going to do so now because that would be unprofessional.

Apparently there is a packet sequence once you’ve authenticated that says re-authenticate me — re-enable, basically opt me back in, turn me back on.

PAUL DUCKLIN

So they can go up to a car with their fake app and they can go unlock the car, goes, sorry, I can’t, it’s offline, the user didn’t buy it.

So they can go, okay, pretend the user bought it, now unlock the car.

GRAHAM CLULEY

This, Duck, this strikes me as an omni-shambles.

PAUL DUCKLIN

This is — well, a duo shambles.

PAUL DUCKLIN

It kind of feels mostly harmless because presumably the idea is if you realise you’ve got one of these things in the car and you go back to the dealer and say, no, I’ve changed my mind, I would like the immobiliser because my son’s just got his licence and I don’t want him grabbing the keys at night and going out for a joyride.

And then they turn it back on.

GRAHAM CLULEY

But you wouldn’t necessarily know that you have one of these devices, would you?

PAUL DUCKLIN

No, you would not.

GRAHAM CLULEY

Especially if the vehicle has been sold a couple of times and it’s still in there.

PAUL DUCKLIN

Or if you bought it and you said, no, I do not want that device, you kind of imagine —

GRAHAM CLULEY

You imagine it hasn’t been installed.

PAUL DUCKLIN

It’s like if they say, hey, we’ve got the optional ski racks thing, or we’ve got the optional sunroof add-on, we’ve got the optional bike rack fitted so you can see how many bicycles you can carry on this.

‘Do you want to buy the bike rack with the car?’ And you go, ‘No, I don’t have any bicycles,’ or, ‘I don’t go skiing.’ Yes. They don’t leave the roof rack on.

They don’t let you have it for free. They take it away. So you would quite reasonably assume that the device was basically deactivated.

GRAHAM CLULEY

So other than getting one of these fake apps, which these researchers have made, other than learning the Bluetooth sequence, how can you know if you have one of these cars installed on your car?

PAUL DUCKLIN

Well, to be fair to carsecurity.com, if you go to their main web page, there is a link in red that says firmware update, and you can click on that.

GRAHAM CLULEY

I’m going there right now.

PAUL DUCKLIN

It has two options. It has, are you an active user or a non-active user?

GRAHAM CLULEY

It’s not exactly flashing red. It’s not sort of saying to me, this is something really, really important to me.

PAUL DUCKLIN

No, I think it’s just a generic thing. I imagine they’ve always had that there.

Maybe they made it red now this is an issue, but it doesn’t say, hey folks, this is more important than you might think.

And if you don’t have one of these or you think you don’t have one of these, you might want to follow the non-active user.

So to be fair to them, there is a way that you can get their app, install it and go through a do I have one of these process.

GRAHAM CLULEY

Who’s going to do this? Well, I mean, there’s a lovely picture of a man in a suit smiling. He’s looking very happy about this.

PAUL DUCKLIN

He’s looking like he was the cat that got the sales commission, Graham, for all these devices, isn’t he? That’s what I thought.

The other problem is that let’s say you’ve now heard this warning from UCSD or you’ve, right, hopefully listened to Smashing Security and thought, hey, maybe I’ve got one of these, maybe I’ll just download the app and do this speculatively.

Obviously, you can understand that CAR want to know, does your car actually have one of these in all likelihood?

And if so, which version does it have, in case they need to send you a slightly different firmware, or in case you’ve got a version where if they send you the new firmware, it won’t work, etc., etc.

So they check your vehicle against their database.

And to do that, you have to give them — this company that has this, as you say, omnishambles bug — you have to type in the VIN, the vehicle identification number of your car.

And give it to them and then they tell you whether they think you’re at risk. So that’s a good way of doing it.

But A, you can only do it by sharing your VIN with a company that you’ve only visited because you’re worried about this bug.

PAUL DUCKLIN

And secondly, it means what if you’re missing from their database?

It’s not like look for Bluetooth signals from my car while the engine’s running and see if you can see packets that probably are yours. That would be a much better way of doing it.

PAUL DUCKLIN

Try and detect whether I’ve actually got one of these, whether your database thinks I have or not.

Because you might have bought the car from a previous owner who insisted on their data being removed or something like that.

So there is a way to find out if you’ve got one of these.

Also, the UCSD researchers have a video that they’ve published, link in show notes, where they show you two things that you can use inside your car to see if you’ll likely have one of these if you’re unaware.

One is that there’s a rather unique looking illuminated button under the dash that they have a picture of with some electronics behind.

And the other thing, irony of ironies, Graham, and I can understand why they did this, Carr was so proud of their security that they persuaded dealers to put a little sticker in the driver’s window that says like protected by Carr.

GRAHAM CLULEY

Oh no. So basically, yes.

PAUL DUCKLIN

Hello world!

GRAHAM CLULEY

This car can be broken into.

JOE

Exactly. This week’s episode is supported by NordLayer.

GRAHAM CLULEY

NordLayer. And before anyone says anything, no, it’s not NordVPN.

JOE

I wasn’t going to say that.

GRAHAM CLULEY

You were absolutely going to say that, Joe. They are both from Nord Security, but NordLayer is a completely different product. NordVPN is for individuals.

NordLayer is a network security platform built for businesses.

JOE

Right, so what does NordLayer actually do?

GRAHAM CLULEY

Well, think about how your team works today. People logging in from home, from hotel Wi-Fi, from coffee shops, from wherever.

JOE

From a sun lounger, hopefully.

GRAHAM CLULEY

You’d be lucky. And the moment someone logs into a company network over an unsecured connection, you’ve got a problem.

GRAHAM CLULEY

Credentials intercepted, phishing attacks, unauthorised access. It’s a scary world out there for travelling workers.

JOE

So NordLayer fixes that.

GRAHAM CLULEY

It gives you encrypted connectivity for your whole team from anywhere, up to 1 gigabyte per second with zero additional hardware required.

But it goes well beyond just encrypting the connection.

You get centralised control over who can access what based on their identity, their device, whether their device is actually compliant.

And if someone leaves the company, money, you revoke their access immediately.

JOE

No more ex-employees still wandering around your systems 6 months later.

GRAHAM CLULEY

No more of that. And it will block malicious sites, risky downloads, dangerous domains, and it can even detect shadow apps.

So if someone on your team has started using some AI tool that your security team hasn’t approved—

GRAHAM CLULEY

Yeah, well, whatever. NordLayer can spot that too. And there’s no complex infrastructure to set up. Apparently you can be up and running in just about 10 minutes.

GRAHAM CLULEY

10 minutes. Plans start from just $8 per user per month. And right now there is a summer sale. New customers get up to 20% off annual plans until the end of August 2026.

Use the code NLsummer26 at checkout.

JOE

Whoa, all I have to do is type in that code at nordlayer.com/smashing and I can get a great deal? Let me write that down.

GRAHAM CLULEY

Yep, go ahead, write it down.

JOE

What’s the code again? I forgot.

GRAHAM CLULEY

NLsummer26.

JOE

Got it. Off to nordlayer.com/smashing I go.

GRAHAM CLULEY

And thanks to NordLayer for supporting the show. And welcome back, and you join us for our favourite part of the show, the part of the show that we like to call Pick of the Week.

PAUL DUCKLIN

Pick of the Week. Pick of the Week.

GRAHAM CLULEY

Pick of the Week is the part of the show where everyone chooses something they like.

Could be a funny story, it could be a book that they’ve read, a TV show, a movie, a record, a podcast, a website, or an app, whatever they like.

It doesn’t have to be security-related necessarily. Well, my pick of the week this week is not security-related. My pick of the week this week is a TV program.

Are you familiar with Diane Morgan, Duck?

PAUL DUCKLIN

Yes, she’s that satirist of intellectual television documentaries.

PAUL DUCKLIN

Philomena Cunk. Was Beethoven good at music? Yeah, I mean, he’s considered to be the best composer of Western classical music ever.

Beethoven wrote that song that goes, “Da da da dum, da da da dum.” What do those lyrics mean? Well, it’s a really strong orchestral motif.

It’s just the word “dum” over and over again. Is it a dig at his audience, or is it German for something?

GRAHAM CLULEY

Philomena Cunk is her alter ego. She also has a comedy series called Mandy, which I enjoy a lot. She’s very funny in her sort of deadpan Bolton way.

PAUL DUCKLIN

Yes, Mandy is the one who is called in for malperformance.

GRAHAM CLULEY

On the banana conveyor belt, killing the tarantulas.

PAUL DUCKLIN

No, the one I remember best was she was called in to get sacked because she’d been rude to customers.

They said, “Mandy, how long have you worked in this call centre?” And she goes, “Oh, about 3 hours.” She’d already basically offended the universe. Oh dear, what’s she done now?

GRAHAM CLULEY

Anyway, she’s got a new TV show on BBC. It’s called Anne Droid, in which she plays a secondhand robot carer.

She is given to an elderly Sue Johnston, who’s grieving the death of her husband a couple of years before.

And she doesn’t want a robot carer, but she’s been given this thing and been told to get on with it. It’s an odd comedy TV show for a few reasons.

PAUL DUCKLIN

It sounds, A, dystopian, and B, as though there could be some things in there that are maybe a little bit disturbing slash sad.

GRAHAM CLULEY

A little bit. I mean, actually, a lot of it is really mundane. It’s clearly very much set in today’s world, but it’s today’s world where it’s totally normal to have a robot carer.

It’s totally normal to have robots delivering takeaways to you or working in shops. It’s all been taken for granted.

So it’s a little bit unusual from that point of view because you imagine it’s going to be more sort of sci-fi than it actually is, but it’s actually fairly down to earth.

Diane Morgan normally is very funny, and I began to watch this and I began to think, it’s not really very funny.

I don’t know that she’s got this quite right, but I stayed for a couple of episodes and I began to get slightly more charmed by it.

And so I would say to people, it is a bit of a slow burner.

But once you get to know some of the characters, you do begin to think, “Actually, this is quite fun.” You meet Sue, who’s the elderly woman. You meet her useless son.

He’s got a horrific jiu-jitsu-loving girlfriend. And you’re beginning to warm to these characters.

And of course, you have the central character of Anne Droid, played by Diane Morgan, who is remarkable in her performance because she walks like a robot, and she doesn’t blink, and she’s very still throughout it.

Physically, it’s astonishing. There are a handful of other robot characters in the series as well, and they all do it extremely impressively.

It’s actually quite a sort of bittersweet little comedy, and it gets rather emotional and touching as well as quite bonkers towards the end.

And by the time I’d got to the 6 episodes, I decided I’d really liked it.

PAUL DUCKLIN

That’s a big investment, Graham. It’s like those 20 minutes you spent filling in the questionnaire for the job. Like, you can’t stop watching now.

GRAHAM CLULEY

I mean, these episodes were only probably about 20, 25 minutes long or whatever, but normally I don’t have the patience, you know, if I’m not enjoying it after a couple of times to say, why am I bothering with this?

But I did happen to watch this and I actually enjoyed it. And my wife at least once laughed out loud. So she was amused.

PAUL DUCKLIN

So what, 7 episodes, 1 laugh? That sounds like comedy gold.

GRAHAM CLULEY

No, there was more than that. There were funny bits, but there was one bit where she guffawed. Anyway, I’m going to recommend it. There are some very amusing bits in it.

GRAHAM CLULEY

I think it’s unusual, but I think our audience who are kind of into the techy bit and our audience who are either fearful of robots entering our lives or really can’t wait for robots to enter their lives and possibly their bedrooms.

I don’t know. Yes. I think they’d like to give it a chance. So if you have access to BBC iPlayer, give it a chance.

I’d just say, if you’re gonna watch it, give it maybe 2 or 3 episodes before you decide if you want to give up on it or not. And you might end up enjoying it as much as I did.

It’s called Android and it’s on BBC iPlayer. And that is my Pick of the Week. Duck, what is your pick of the week?

PAUL DUCKLIN

Well, my pick of the week, I’m going in the other direction. Well, temporarily. Okay. So I’m having a historical moment here.

And this is just because the weather’s been unusually splendid, perhaps, in the UK.

It hasn’t rained for ages, and it’s been nice and sunny and bright until late, which is a sort of a cyclist who likes exploring the local area’s dream.

I’ve been doing a lot of late afternoon, early evening rides to what you might call low-key, low-impact local sightseeing.

So things that you can do with public transport on foot by bicycle or some combination where you don’t need a car, you don’t have to pay for parking, you don’t pay for admission.

It’s not commercialised, but it tells a fascinating local and to some way sort of pan-European or even global historical story about, you know, what we used to be like.

Not just before the robots, but, you know, before the Industrial Revolution.

And so deliberately trying to avoid the sites that are very commercialised, everyone wants to go to, which you can reach by bike just from where I am, like say Stonehenge, right?

Or Stratford-upon-Avon, which is, you know, a pilgrimage for Shakespeare fans. I mean, it’s lovely to go there, but it’s kind of—

GRAHAM CLULEY

There’s lots of souvenir shops.

PAUL DUCKLIN

Yeah, it’s sort of like — it’s Shakespeare Disneyland, if you know what I mean.

PAUL DUCKLIN

These things that I’ve been to, they’ve just been there on a hillside or in a field, and they’re just sitting there. You often don’t see that many people there at all.

Some of them, I’ve rarely ever met anyone else, but they’re combining Neolithic, so that’s sort of Stone Age, Bronze and Iron Age, and the Roman occupation era in Oxfordshire.

And so the places I’ve visited lately are the Roman villa at North Leigh. There is a really nice mosaic there that’s well preserved.

And if you’re in Oxfordshire, the August bank holiday weekends, it’s actually open so you can go in and actually go up close to it.

And the other places I’ve been to are the Horstone burial chamber, which is in northwest Oxfordshire, and the Hawkstone, which is just a single stone about 2 metres high in a farmer’s field.

It’s been standing there for 5,500 years.

PAUL DUCKLIN

They plant barley right up to it, and it’s just there. Nobody knows quite what it was for, but there it’s been.

And then the last thing, which is probably the most famous of them, is the White Horse at Uffington.

PAUL DUCKLIN

Which is a chalk horse on the hillside on the Ridgeway. And that is my pick of the week.

GRAHAM CLULEY

Great picks of the week there. And that just about wraps up the show for this week. Thank you so much, Duck, for joining us.

I’m sure lots of our listeners who’d love to follow you online — what’s the best way for them to do that, find out what you’re up to?

PAUL DUCKLIN

If you’re on LinkedIn, follow me. Just search for Paul Ducklin or P. Ducklin, or just head to my website, pducklin.com/about.

And if you’re looking for a great presenter, writer, and all-round cybersecurity commentator, non-AI-based good guy, I am available for hire.

GRAHAM CLULEY

And of course, we are on social media as well. You can find Smashing Security on Bluesky and Reddit and Mastodon.

You can find me, Graham Cluley, on those places and on LinkedIn as well. And don’t forget to ensure that you never miss another episode.

Follow Smashing Security in your favourite podcast app such as Apple Podcasts, Spotify, and Pocket Casts.

For episode show notes, sponsorship info, and the entire back catalogue of 478 episodes, check out smashingsecurity.com. Until next time. Tchau, bye-bye.

PAUL DUCKLIN

Bye everyone.

GRAHAM CLULEY

You’ve been listening to Smashing Security with me, Graham Cluley, and huge thanks of course to Duck for joining us this week and to this episode’s sponsors, Arctic Wolf, NordLayer, and Vanta.

And you know what else — we’ve really got to thank our super duper Smashing Security patrons, those members of Smashing Security Plus who get their episodes early and without ads.

And they also get the benefit of having their names read out, picked out of the hat and spoken about at random, possibly having their names mocked.

So let’s take a look at some of our patrons this week. We’ve got Just Nate Please. So Nate, we hear your please and we’re very grateful that you’re here.

Also big cheers to Benjamin Harouth and Henry Walshaw, and also to Ashley Woodhall. That’s a name that sounds like a lovely country walk.

Huge thanks to Jonathan Haddock, a fine name, though we now have an overwhelming urge to go to a chip shop. And who else?

Jamie Forster, Bobby Hendrix, and Panda Bear, who is possibly our most enigmatic supporter.

And rounding things out for this week, we have Sammy Dozer, still the most appetising name on the entire membership list, and Richard Anand, who sounds like he should be chairing a very important committee and probably is.

Those are just a few members of Smashing Security Plus. Maybe you’d like to join them. If so, go to smashingsecurity.com/plus for all of the details.

And for a few pennies every month, which will be very gratefully received, you will have all the benefits that those folks have.

Now, there are other ways you can support the show which don’t cost a penny. You can like, you can subscribe, you can leave a 5-star review. Oh, that’d be nice.

Leave it wherever you listen. Tell your friends about the show and spread the word. Every bit helps. And I really do appreciate it. So until next time, cheerio, bye-bye!

Leave a Reply