Tips from a hacker: three measures to protect yourself from scams in the wave of artificial intelligence

The cell phone became an ubiquitous device. We use it for everything: communicate, work, do paperwork and entertain ourselves. But like everything, depending so much on the same tool can be a problem.

There is a simple exercise to measure how much we depend on technology which consists of imagining that suddenly the cell phone does not turn on. There is no access to WhatsApp, email, banking applications, contacts or work tools. Much of everyday life is suspended behind a black screen, to which we return again and again like when we turn on the light switch even after a power outage. Due to this growing technological dependence, we need basic knowledge of how to safely use technology to avoid problems, whether due to failures, malfunctions, device theft, hacking, or cyber scams.

César Cerrudo is an Argentine hacker who has been working for more than 25 years thinking about what happens when technology fails, someone manages to manipulate it or a user inadvertently hands over the access key. The researcher (“hacker”, in slang, someone who tries to understand how something works and eventually breaks it) discovered vulnerabilities in products from Microsoft, Oracle and IBM, among other large companies, conducted several hacking investigations at events in different countries and gained international notoriety by studying the systems that regulated traffic in cities in the United States and other countries: he hacked the traffic lights.

His experience is now condensed into “simple and practical advice” in an updated version of A Hacker’s Guide to Security, a book aimed at non-technical users of all ages. Among its recommendations, three basic measures can be extracted that reduce a good part of the daily risks:

1. Two-step authentication

The first is to activate two-step authentication in email, social networks, WhatsApp and any service that handles money or sensitive information. This way a code will be required in addition to the password, so that if someone gets our password they will not be able to access our account. Cerrudo recommends using an authentication app when available, because SMS codes can be exposed if someone takes control of the phone line.

2. Do not repeat passwords

The second is to use a different password for each account and store them in a manager. A breach in a minor service can hand over the key to an email or bank account, as cybercriminals try the same password on all of the potential victim’s accounts. It is also advisable to activate a passkey when the platform offers it: it allows entry using the fingerprint, face or device code and is better resistant to phishing attacks.

3. Always distrust

The third requires always distrusting and stopping any message that urgently requests money, passwords or codes and verifying the sender through a channel other than the one through which the message was received. If a family member or friend supposedly writes, you can ask them a question whose answer only you both know or use a secret word. It’s a simple defense against stolen accounts, voice clones, and fake videos.

Of course, none of these precautions come backinvulnerable to a user, but together they close some of the simplest paths that criminals take advantage of. “Learning the basics is quite easy and with that you can avoid the vast majority of problems,” says Cerrudo.

The background that made him famous is usually summarized by saying that “he hacked the traffic lights in New York”. The technical scope was a little more than that: Cerrudo discovered failures in wireless sensors installed under the pavement, used to inform control systems if a street was congested or clear.

The researcher conducted tests inSeattle, New York and Washingtonand found that The information traveled without encryption or proper authentication. He reported it, so that the different administrations could fix it, by demonstrating that an attacker could send false data and make the system make wrong decisions, causing possible chaos in the traffic of large cities. It did not alter lights or cause traffic problems.

From that work, Cerrudo expanded his research towards smart cities and critical infrastructures. Here, an in-depth talk for those who want to go deeper beyond the three measures that he recommends adopting on a personal level with our personal accounts, telephone numbers and online information.

Thinking like a hacker: SIM pin, secure crypto and measures against grooming

─Why is it important for an ordinary citizen to start adopting a “hacker mentality” to protect their privacy?

─Today we depend too much on technology. An example that I always give is to think what would happen if tomorrow we woke up, looked at our cell phone and it turned out that it didn’t work in any way. How would that affect our day, work, study or family? We would surely have a lot of problems.

─What does it mean to adopt that mentality?

─Understand what the most common hacks, cyberattacks and online scams are like to properly protect yourself. Many people think it is difficult, but learning the basics is quite easy and with that you can avoid the vast majority of problems. The more we know and the more prepared we are, the less potential victims we will be.

─In the book you say that “we pay with our privacy and our data.” What is the most dangerous digital trace that we leave without realizing it?

─Almost everything we do with technology is recorded, whether on the internet, on our Smart TV or in applications. By accepting the terms of use, we agree to be monitored, since companies keep everything we do. With that information and artificial intelligence, they end up knowing us better than ourselves.

─Will passwords end up disappearing and will we migrate to passkeys?

─Little by little they are going to die, since passwords are an old system andcomplicated. Biometric systems allow us to authenticate ourselves using facial recognition or fingerprint. Little by little they will be incorporated into applications and will make passwords no longer so necessary.

─Something that the book also points out: few users know thatthe SIM card has a PIN. Why does this measure help?

It serves to protect our telephone line if we lose our cell phone or it is stolen. Even if the phone is locked, they can remove the SIM card, put it in another device and receive password recovery or two-factor authentication codes via SMS. They could also take control of WhatsApp and any application that depends on the line. This is why it is important to put a PIN on the SIM card to block the use of the telephone line. Of course: don’t forget it.

─What is the difference between having cryptocurrencies on an exchange platform and using a cold wallet?

─Almost no exchange platform or centralized service in the crypto world has the funds it manages insured. If the platform is hacked, we can lose everything and no one will be held responsible. It is recommended to use cold wallets, where security depends on us. Seed phrases (which are used to recover cryptocurrencies if we lose wallets or access) must be physically recorded on paper or metal and kept in a very safe place.

─How can parents set limits without breaking the children’s trust?

─The main thing is to talk to kids and explain the possible dangers as soon as they start using devices. Restrictions should also be set using parental control tools. You have to accompany them and know what they use, what applications they use and who they communicate with, without being too invasive. Letting a child use devices without any control and guidance is like letting him go outside alone in a big city without explaining the possible dangers and how to avoid them, it can end very badly.

─If we discover that we have been hacked, why deleting messages can harm a report?

─In the event of a hack, it is important to file a report and present evidence. That is why messages or information should not be deleted or modified, so that they can be used as evidence without problems.

─Why is it not advisable to try to “hack back” either?

─Even if we have been hacked and we know or suspect who it was, trying to hack that person or asking someone to do it is illegal. It can cause us many legal problems. It has happened to me several times that they have asked me to hack someone because they hacked them or also to hack their ex-partner because they did something bad to them and I always have to explain to them that this is illegal.

─What simple technique do you recommend if the voice or video of a family member asking for money or something out of the ordinary on WhatsApp seems real but suspicious?

─It is becoming increasingly difficult to distinguish what is real and what is not. You can clone a person’s voice and even generate videos in real time pretending to be another person. If someone asks for money or personal information, make sure they are who they say they are. If you claim to be a family member or friend, we may ask you to tell us something that only we and that person know or usea previously agreed keyword. If they say they are contacting us from a company, we must verify if they are doing so from an official account or phone number. You should never rush before providing information, you should always distrust first and then verify.

From traffic lights to threats against a city

Cerrudo’s research led him to study a larger problem. As cities connect transportation, energy and water, a computer failure can have consequences in the physical world.

─How close are we to seeing attacks that affect the physical security of a city?

─We depend too much on technology and this dependence continues to grow. With artificial intelligence, it is becoming increasingly powerful and autonomous. This brings great benefits and associated dangers. In addition, advances such as humanoid robots and self-driving cars continue to arrive.

─What should citizens demand from governments?

─At the government level it is important that there is awareness about the dangers and that the necessary investments are made to avoid possible attacks. Critical infrastructure companies must also be required and controlled to have an excellent level of security.

─Who could carry out an attack of that magnitude?

─The possibility of cyberattacks with great impact is always latent. It is not common, because cybercriminals generally do not do that. It is more feasible when there are conflicts between countries, since governments have more access to resources and dangerous cyber weapons. Therefore, some countries would have the capacity and the possibility of carrying out truly destructive cyberattacks that affect thousands of people.

The updated edition of the book A Hacker’s Guide to Security brings together warnings and instructions on passwords, phones, Wi-Fi networks, cryptocurrencies, artificial intelligence and child protection. It is available to download for free from this site, without registration, in PDF and Epub, and has versions in Spanish, English and Portuguese.

“Together with the book, a new initiative Mission 1 Million is launched, which has the objective of ensuring that 1 million people know how to defend themselves against threats For this, we made several resources available such as an Interactive Test to quickly determine how hackable you are, a Simulator to face cheats and see if you can detect them (it can be done individually or as a family to learn by playing), an Interactive Academy to learn short and practical lessons, Infographics to learn quickly in graphic form and resources to give workshops or classes online.schools and companies. All this for free to use freely”, closes the hacker.

At the end of the day, defense does not depend on being up to date with the latest threats but on a state of alert that, once internalized, becomes commonplace.

By Editor

One thought on “Tips from a hacker: three measures to protect yourself from scams in the wave of artificial intelligence”

Leave a Reply