back to article Phishing works so well crims won't bother with deepfakes, says Sophos chap

Panic over the risk of deepfake scams is completely overblown, according to a senior security adviser for UK-based infosec company Sophos. "The thing with deepfakes is that we aren't seeing a lot of it," Sophos researcher John Shier told El Reg last week. Shier said current deepfakes – AI generated videos that mimic humans – …

  1. Andy 73 Silver badge

    But...

    ... are we sure this is "Sophos researcher John Shier" who said that? It could be those DeepFake guys trying to put us all off the scent...

    1. Anonymous Coward
      Coat

      Re: But...

      How do we know that you, allegedly Andy 73, aren't the real deep fake trying to get Sophos to back off?

  2. imanidiot Silver badge

    So he's saying we shouldn't worry about it for very low level, low effort crimes where simple social engineering techniques such as phising work fine. I don't think the majority of security conscious people are very worried about that. It's the high value, high effort targets where this can make a massive difference and I for one do still think there's plenty of organisations that SHOULD worry about the risk and agree on verification methods if high-value deals/transactions have to be discussed or authorized via video chat.

    1. Charlie Clark Silver badge

      Oh sure, office, I don't mind giving you my password: it's gizmo…

      For video calls, 2FA, as already exists in good chat programs is available.

    2. Dave314159ggggdffsdds Silver badge

      "It's the high value, high effort targets where this can make a massive difference"

      That assumes such targets are harder to fool. In my experience that is not a valid assumption. In practically any office in the world, you can walk into reception and say 'hi, I'm here to pick up the backup tapes[/usb stick/whatever]' and someone will go and get them for you. If they don't have any ready, someone will prepare them. No-one will ask you who you are or why you're picking them up.

      1. Yet Another Anonymous coward Silver badge

        If you have a hi-vis vest and a clipboard you can probably just take the servers

        1. Dave314159ggggdffsdds Silver badge

          No probably about it. I've literally done that. We were supposed to be collecting the servers so weren't stealing them, but it hadn't been arranged properly with the people on the ground, and they let us take them anyway because we asked nicely.

          I used to work for a relocation company. There was also the time another team relocated an entire office, and the only problem was it was the wrong office. No-one stopped them.

          1. Yet Another Anonymous coward Silver badge

            Smart bomb targeting gui, be really careful with the 'FROM" and 'TO" fields

  3. Pete 2 Silver badge

    Trust me, I'm a ...

    > "People will give up info if you just ask nicely,"

    And they will do that especially quickly if they think they are talking to a person in authority. Where "authority" can be anyone from a doctor down to a gutter-press journalist. Or anyone faking someone in those positions.

    Until people develop a sense of wariness, scepticism and suspicion, this will continue to be the richest seam for scammers to mine. And it seems that every generation brings a fresh cohort of innocent, trusting, victims.

    1. ThatOne Silver badge
      Devil

      Re: Trust me, I'm a ...

      You're right, but on the other side there are the people wanting to make a quick buck out of this new scare, and who desperately need to convince you that the end is nigh - unless you buy subscribe to their Deepfake-Away™© service...

    2. Version 1.0 Silver badge
      Joke

      Re: Trust me, I'm a ...

      > "People will give up info if you just ask nicely,"

      "You know the rules and so do I, a full commitment's what I'm thinking of, you wouldn't get this from any other app. I just wanna tell you how I'm feeling, gotta make you understand, never gonna give you up."

      1. yetanotheraoc Silver badge

        Re: Trust me, I'm a ...

        Rickrolled by a deep-fake, perfect for building trust.

    3. yetanotheraoc Silver badge

      Re: Trust me, I'm a ...

      Me: You want what?!

      Them: Trust me, I'm the new corporate chatbot.

      Me: ???

      Them: Didn't you get the memo? The old corporate chatbot is EOL.

      Me: Oh, that's all right then.

      (We actually have a corporate chatbot! It has all the same defects as chatbots everywhere.)

      1. Yet Another Anonymous coward Silver badge

        Re: Trust me, I'm a ...

        We're safe, we have an official password inspector - they just emailed me to check mine.

      2. ThatOne Silver badge
        Devil

        Re: Trust me, I'm a ...

        > (We actually have a corporate chatbot! It has all the same defects as chatbots everywhere.)

        That's no way to talk about your manager!

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like