Submind YouTube summaries
Thumbnail for #powertalkshow |PSYCHOLOGY OF HACKING | ARE YOUR BANK ACCOUNTS  SAFE?

#powertalkshow |PSYCHOLOGY OF HACKING | ARE YOUR BANK ACCOUNTS SAFE?

Watch on YouTube

Video summary

The Power Talk Show episode featuring host Brian Squa and Christopher Hayer delves into the critical intersection of psychology and cybersecurity, emphasizing that modern hacking often exploits human behavior rather than just technical flaws. The discussion highlights how individuals in Kenya frequently overshare sensitive personal details on social media, such as locations and family information, which allows attackers to build psychological profiles for targeted attacks. This vulnerability is compounded by sophisticated social engineering tactics like phishing, where scammers induce fear or urgency through fake messages about frozen accounts or fabricated windfalls designed to trigger emotional responses that bypass logical thinking. Furthermore, the rise of AI-powered threats has made these attacks more insidious, with voice cloning and deepfakes enabling criminals to trick employees into transferring large sums of money using forged audio notes from their bosses. To combat these evolving dangers, experts advocate for a security approach that treats employees as humans with emotions rather than machines, promoting a bottom-up awareness model where individuals pause before reacting to urgent messages and verify sources rigorously. Practical defenses include using strong, unique passwords of at least twelve characters, enabling two-factor authentication via authenticator apps instead of SMS, and utilizing password managers to secure credentials. Organizations must also be vigilant for indicators of compromise such as unexpected notifications, unknown active sessions, deleted files, and server logs showing communication with suspicious IP addresses, requiring them to notify the Office of the Data Protection Commissioner within seventy-two hours of any breach. The legal landscape has shifted significantly with the Cyber Crime Act of 2018, which now legally defines and penalizes interference with system functionality, while also establishing strict rules for digital evidence admissibility in court that require original data preservation rather than mere screenshots. Beyond individual and organizational measures, the conversation addresses systemic challenges such as government vulnerabilities caused by slow procurement processes and budget constraints that delay the acquisition of essential security solutions like firewalls. Under the Data Protection Act of 2019, primary data collectors remain legally responsible even when third parties process information, reinforcing the need for robust governance structures. A major hurdle identified is the severe shortage of experienced cybersecurity professionals in Kenya due to a lack of local institutions teaching advanced concepts like cyber psychology and human hacking. To bridge this gap and help individuals navigate generational patterns of mistakes, Christopher Hayer promotes his book, *The Error: The Teacher I Never Wanted*, which offers wisdom gained from errors and is available for purchase through his website or phone number, serving as a resource for understanding the complex dynamics of online safety.
Read the full video transcript
All right. Absolutely. Good evening to you. Thank you so much for joining us right here on Power Talk Show. My good name is Brian Squa and in just a bit we'll be posting our question of the day. So we're inviting your thoughts and your feedback on it. Now tonight we delve into m human human hacking. Now in the baming Kenyan digital landscape, a click, a like, a share or even swiping could cost you just more than data. With Jenzis being the first generation to ever fully live online, they're susceptible and even prone to things like, you know, hacking, threats, leaks, and even intense surveillance. with my guest joining me live in studio is going to help me unpack how some of these cyber attacks and threats hitting your mobile phone and device are redefining and shaping rules and rewriting laws of online safety. And I've been engaging with Christopher Hayer. He's a coordinator at Kenya Cyber Security and Forensics Association. Great to have you. Good evening. >> Thank you, sir. >> Right. So, let's let's get to hear from you first and your profile a little bit. Maybe you can start off from what are some of the annoying online habits. I'm using annoying so that we just pinpoint exactly but maybe they're concerning also in a good way or a bad way about Kenyans and how they navigate through the ever booming digital landscape in Kenya. >> Um thank you Brad for for this opportunity. Now one thing that annoys me as a cyber security practitioner is that Kenyans we tend to overshare. You're going to Mombasa you post online. You are taking your kids to school you post online and even you tell us your their details. Now you're doing this. You don't know that as a hacker I'm able to extract location from these pictures that you're sharing with me. As a hacker, I just need um 3 seconds of your voice in whichever maybe it could be I can get it from a video >> to to perform some other types of attacks based on on um on on on your voice. So they tend to overshare and I think by oversharing that information that data you giving a hacker a script about your life. So I'm going to use this information to do what? To perform some kind of attack on you. >> So what would you recommend though? Should they limit what they share? Cuz when you look at a person who is a content creator, Jenzi who's an influencer, they're all about posting updates. I'm at this club. Come, let's have fun. I'm going to do this event. I'm going to this TV interview like Chris. Aren't you not informing your followers and your fans of you know your journey and what you're doing? And why is it dangerous then? >> Um Brian, we need to have a clear boundary between content creation and personal data. Um I'm not saying that you should not uh share what you're doing but we must have a clear boundary between what you are sharing and your own safety. Like for instance, um maybe I have three kids. I'm going to post their their their full names on social media. I'm going to post my my wife details on social media. I'm going to post where I work, the office that I sit on social media. You see, these are personal data. So we need to have a clear boundary of what we post online in terms of content creation and also we also need to have a a clear boundary of um of of of personal safety. Now what is the danger of all these things? Now you share your personal data on social media. You're basically giving a hacker a script about your life. >> I know where you live. I know where you work. I know the kids that you have. I know everything about you. information. I simply need to do what? To understand something about you to get some information about you to to come up with a clear profile about the target. Then I come up with a psych psychological weapon that that I I will use against you. So you see the the the correct psychological weapon against you at the right time to make you a victim >> right >> of any type of attack. >> So let me ask you before you lose your train of thought. What should you not post and what should you post? Cuz you know those are those are restrictions when you look at it deeply. It's like you're redefining how somebody should operate using their social media platforms. So, are there limits to what specific stuff you should share online and what you should not? What would you pinpoint exactly of what you should share and what you shouldn't specifically for an individual? >> Um, you can share general data, general information. This guy is Chris. Chris is a cyber security engineer. You can share that. But you should not share your personal information. Like for instance, my ID number. Why should I share my ID number on social media? >> Are there people that share ID numbers? Yes, they do. They take a selfie of screenshot of their ID the voters card. >> They share on the on the internet so that other people can see. Oh. >> Yes. Exactly. So we we should not share personal data. The year of birth. Why should you share your your date of birth? >> These are the things that as a hack I need to come up with a profile about you. >> Yeah. >> Right. uh and maybe would you say is this what drove you into this uh profession because you are the coordinator at cyber and at Kenya cyber security and forensics association. So maybe what makes your profile and the passion that drives you to be passionate about this conversation in the cyber security space. >> I like solving challenges. I like um dealing with for me difficult things. >> Yeah. Now I realize that cyber security is more of hacking play around with a computer system to security to identify those gaps. So that's what I love. So the fact that it's challenging it needs some critical thinking is what drove me into these things. I didn't want to do something that is boring. Come on. >> Yeah. Right. Of course. But you know being a tech when you're a cyber security expert it means your your your personality as well could be more laidback. your focus like most techies are actually nonchalant laidback and just you know less words they're more into tech stuff researching and all that yeah so I believe you are suitable for this too and also maybe let's get to start of understanding what are some of the common cyber attacks that happened to a daily average Kenyan you know because we are all about you know social media and if you look at Jensen even when you look at the mandos and everything that happened it was all online they never met in person they only met during protest and demonstration So how do we debunk that and make it you know a conversation that should constantly continue to be there even though we are trying to reshape the rules of navigating online but it's a space that everyone should be there but with safety. So maybe what are some of the common threats? >> Uh the common threats the I want to answer your question. It's it's um it's more social engineering attacks where social engineering attacks involves manipulating people into revealing some sensitive information that me as a hacker I'll use them against them. >> Yeah. So and the most common example in Kenya is fishing attack where I draft you a message I'm telling you hi Brian this and this I'm from the bank your account has been frozen click here if you think this is a problem to do what >> to unlock or to do so so because of that message in that message there is fear already in that message your account has been frozen then click here before 2 hours the aspect of urgency now coming in what happens when you are under fear and urgency logical thinking normally stops once logical thinging stops. You don't verify any of these information. So you went you will go ahead click those funny funny links then at the end of the day what will happen you lose money. Like today I was solving a particular case >> where >> someone um pretending to be from safar >> calls someone that I know. >> Mhm. Uh this person is telling this this now someone that I know that um we are calling you from Safariccom Empessa. We realize that your account has done this and this. So we are supposed to verify some information about you for us to do what to unlock. >> This person does not know about the online scams. So he goes ahead click those buttons. He has been instructed to do so. Then at the end of the day you see >> there there was money transfer from this account to the >> Yes. to the scammers. So the fishing attack is the most common form of of hack that is that we are experiencing as a country, >> right? >> Uh for somebody who's watching this conversation and maybe they've already clear cuz some of those links are very enticing actually. They'll be like click for good luck. You just won 1 million uh USD. Um somebody and so from New York City I sent a container. Click on this link. And then it ends up even you know creating a site and you end up creating a site. you log in and eventually end up being logged out of you know your for example if it's your mobile device or your computer etc. So for somebody who's watching this conversation and they want to understand some of the safety measures that they can employ online so that you know they ensure that there's safety whenever anything happens. What would you advise them and what should they do individually and then institutional wise but maybe we can get to some of the cyber attacks that are prone to institutions. Let's finish up with individuals mobile phone computer etc. What would you advise them >> now? Um Brian before we understand how to tackle those kind of attacks, we need to understand what normally happens. Yes. >> Like for instance, the the the best example used about you have received a container from this and this it has this and this. You see human beings you are wired to receive. >> Anytime Brian you receive something, you become happy. >> When you're happy, what happens? Your body produces dopamine hormone. Dopamine hormone is the happy hormone. Happy hormone that makes us feel excited. >> Once that hormone is released in the body, logical thinking >> escapes, travels. >> Yes. Once that one is gone, will you verify? >> Yeah. >> You will not verify any of this information. >> You have been told that I've sent a container worthy 10 million. You go ahead and do what? >> And and and and receive. So the best way now to tackle this, we understand, we accept that first of all, we are human beings. We have emotions, we make decisions, we trust. So the first thing that um uh that we have to do number one is first of all to pause. Whenever you receive a message, a call, you pause, you you pause, then you think about it. Ask yourself what are some of the psychological emotions is this message trying to trigger in me? >> Right? >> They'll trigger happiness in you. they'll trigger some stress in you, pressure in you, some aspect of urgency in you. So as you pause and ask yourself about this um this question, what are some of the >> emotions that got triggered by this message? Now you move to the next phase. >> The next phase is now to verify. >> Now you verify if this information is genuine. If this email is coming from the real IT support, if this email or or if this call is coming from the real bank. So you do what? You verify this information. So now verifying continue. If it's clicking, it's upon you. >> Yeah. >> But click only once you are verified. >> So that would refer to an individual profile or an institution. >> Both in this case both. For the organizations you ask about the common attacks that happens in an organization. Still we are coming back to human Brian the the in cyber security the weakest link is not technology it's human being operating these computers so even the hackers who want to hack a particular organization company they not go for those servers cuz they know those servers are very much secured they'll come for this admin who is a human being >> yeah so >> and now in a in in um in an organization setup there's a problem that we normally we normally do in form of we train people We create awareness but we're treating these people as machines. >> Yeah, >> that's the problem. >> Once you treat once you treat this stuff as a machine, it means that you're giving him or her a manual to follow, create a strong password, but you're forgetting this is a person, this is a human being who has emotions, who make decisions, who is under stress, who is under pressure. So if there is an attack that will come to your organization, it will not for me as a hack, I'll not focus on that server. I'll focus on this admin who is a human being. So at the end of the day >> so solution to that how do we do >> um we adopt the bottom up model for security awareness in an organization. What do I mean >> organizations like no before >> they they they deploy this model the know the bottom up the bottom up. look at that stuff, treat him or her as a human being, >> get to understand what he or she knows about cyber security, then build from that. >> Absolutely. >> That is now the bottom up model, >> right? >> And maybe uh in just a bit uh you'll tell us so what exactly is being is hacking. Yeah, if you to explain it in simple term for somebody who's just joining in in the conversation. But online, we are asking you what online scum have you ever fallen for? Please let us know. We've just talked about fishing. Clicking on a link, you've won a container. Oh, click this. You have 1 million USD that's on the way, but it has just been deposited in your bank. I think the common one is somebody calls you and tells you uh they they first of all, they send you an Empessa message and it it has hidden the number and the amount, right? And they're not telling you where that Empessa message is from, but also it's not from Empessa, right? So, please, what other forms of hacking or scams have you endured online? And the hashtag is power talkshu right 24 channel at brand circle101 basically as we pivot before we get to um how modern day hacking looks like for an institution and we'll get to so many other as well that have happened in the country uh what is hacking in general if you to explain it to Alana who's just tuned in right now. >> Hacking um is actually gaining unauthorized access into a particular system. It could be an office. It could be a room. It could be a computer unauthorized access meaning you are not authorized you're not permitted to gain access to do something in that particular computer. So once you have that unauthorized access into the system then you can steal some information or some data then you're going now to use this data that you have stolen from this computer to perform some other types of now >> malicious activities like maybe steal money. >> I have the information I can go ahead and do the >> data. Yeah. And you know we live in a world of data renting. I think with big tech there this there's one of the tech influencers who was explaining that we're heading to a cyber world where institutions will be able to buy data from other countries and use it as statistics. And somebody brought in a conversation on health records you know and the funding etc. I found it to be really interesting. But let's deep dive into how does modern hacking look like today in this world we are living in right now. Nowadays we are using AI in almost everything. So the type of of hacking activities that normally takes place. We don't nowadays rely on traditional methods of hacking like I need to come up with to come here with my computer connect it to this and this run these tools try this and this. No almost um every form of hacking nowadays it's AI powered. you find that this is connected to a particular like the one I was telling you the voice cloning where I simply need 3 seconds of your voice then I can generate >> um hours of your voice maybe giving out instructions just need your voice for 3 seconds then I can come up with that um with that clip >> another another example is now the fishing that you you talked about AI now can generate those fishing links those fishing males within seconds you just give it a prompt then you have a fishing a fishing email >> yes >> on on on the other side >> again uh for the defensive side we're also using AI now to do what to protect these systems that's why he says that now the modern form of hacking does not focus on systems we're now focusing on human being >> so you're trying to like impersonate or create an image of this person and even use it to you know escalate other you know hacking activities. >> Yes. Exactly. Like let me give you an example of the the notorious Facebook hack. You realize that this account has been compromised. This guy sends you a link. Brian I saw you in this video. Click to view. You see by sending you that um that by sending you that link telling you that I'm video click here to view. There is that curiosity in you. because so systems are improving in terms of security but human beings we still human we still have emotions we still making decisions you're still trusting so that is now what the hackers are using AI to exploit >> yeah for a person who smelling a rat and by that I mean trying to be suspicious that you know what I feel like somebody accessed this server and manipulated or added something or adjusted something or maybe there's a bug or infiltration of some sorts cuz you know virus etc. Are there like telltale signs or digital footprints that hackers leave or trail for a person maybe who's not who is not a cyber security expert like you are they can tell there's a possibility that's why I said smelling a rat there's a possibility somebody logged in or was here and they adjusted stuff what are they what are the cultural signs that your system your computer your mobile phone your accounts has been infiltrated or attacked >> of course uh those are what we call the indicators of compromise that someone was here. Yes. I'm not sure but someone I suspect someone was here. For instance, if it's a phone, you'll see maybe some messages without you knowing. Then you will get some notifications. For this case, maybe it's an email notific. The same thing with Facebook. They'll tell you that you're active in this device at a particular location. So at the end of the day those indicators >> for business setup of course the servers it has what we call the logs. So when you collect these logs together >> there is a a unique IP address IP address that you even don't know a domain name maybe that you even don't know and you realize that this computer was communicating with another computer that even don't know where it exists and of course some data has been deleted manipulated or even transferred between your computer or your server to the remote machine then that one is an indicator of compromise. What are you supposed to do? M will be the next question. >> Yeah, maybe >> for the case of business, for the case of business and you realize that there has been a data breach cuz once the data >> has been transferred to another party that is not associated with that organization, >> then that one is a data breach. You have to notify the OPC within 72 hours and all the stakeholders. >> Yeah. And I want us now that you mentioned AI and data for example now with artificial intelligence how are hackers using it to extort Kenyans now with the voice cloning are there like maybe stories wild stories that you've heard in the cyber security space in terms of you guys doing investigations etc that you know hackers are using AI to benefit from Kenyans without their consent. I've dealt with uh some even last week the one for AI cloning >> where an employee walks in the office. It is a Monday morning. It is just after weekend though hangover >> fatigue. Mhm. >> Yeah. >> Right. >> A message comes in. Hey Morin, transfer some money to this account. I'm in a meeting. I'll sign later. Within few seconds, Moren receives now a voice to confirm a voice note from the boss >> to confirm >> and within few minutes that business or that company had already lost 700,000 transferred to the to a particular account. >> Yeah. >> So he was now conducted to perform the forensic >> forensic analysis. >> Yes. To assist them >> to see them. So that is now the the the weird story I've heard about it cuz upon analyzing all these things we realized that this voice note that came in was AI generated. >> Mhm. The message that came in was also a fake. It was it was it was a form of a screenshot. Come and sign later, >> right? >> But that screenshot, it was AIDated. So I was able to come up with search with a story or I mean with a report of all those things and realized that everything there was AI powered generated and that made the company lose some good money. >> Yeah. And maybe how does it affect now investigative strategies and approach to that cuz I'm sure an AI AI evidence can it needs an expertise eye or panoramic lens for you to spot it. uh how does it affect further piecing up of uh investig rather of evidence that leads to a hypothesis that now will result to an investigation if it's AI or >> because we have been having challenges doing investigations by the way because the hackers are not stupid these guys will use proxy these guys will use the VPN so you cannot even establish that these guys in Nairobi >> you try to to to to perform forensics >> right >> towia Roman in real sense these guys in Kilimani here in Nairobi now with AI again we still have that challenge you're trying to look at this you're trying to use this tool to do this and this but those guys are smart enough that at a point who want to feature metadata of all those images >> but now when you go further >> this is an email they claim it came from this particular person >> at this time on this date >> right >> let's go now to the mail server do we have such a log >> right >> we don't have so that what what does that tell us this this fake image generated >> it's crucial to prove this and this >> right >> and maybe are there tools that you guys use as a cyber forensic experts >> yeah we have I'll just uh I just tell you one >> the image eye >> image eye >> Mhm. that we use now to analyze and the pictures. You have a picture, you upload it there. It will give you the exact location where it was taken, the exact time where it was taken, the device that was used to take this uh picture, >> the phone >> or the media or the mode of of transfer. This image was transferred from this point A to point B and among other metadata information that you need, >> right? Maybe would you say that that's one of the biggest challenges that uh is facing uh cyber security professionals lack of adequate material or equipment to let's say uh take after an investigation that especially with hacking and we are going to deep dive into the recent hacks and defacing of government sites etc. Would you say that's one of like the major, you know, weigh down in your operations as a professional in the cyber security world? >> Um, >> in Kenya specifically, US. Yes. >> Number one, there's a there's a there's a problem in Kenya. We don't have enough institutions that are teaching cyber security. >> Cyber psychology and human hacking is a new concept in cyber security. Not just new, but it has been around for for quite some time. Yeah. But in Kenya, have you even heard have you ever heard about cyber psychology? Even they ask >> not yet. >> Now if you have never heard about it, how many institutions in Kenya do you think they're teaching that? >> Right. We having a conversation at least right now they've gotten a glimpse of it. Yeah, >> there's none zero institution teaching about cyber psychology and human hacking. But now that is where you are heading as a cyber security issues. They all most of them are now revolving around around cyber psychology and human hacking. But we don't have any institution that is teaching cyber psychology. I know you ask me I do research. >> I'm a researcher. I do a lot of research on cyber psychology and human hacking cuz I know that is where we are in terms of cyber security. Another challenge as a security now personal challenge is that people don't trust you. >> Yes. But I can tell you that there's a time I went to a bank then I was making a phone call the security officer in that bank. Why? Because he believes that this a hacker is here to hack our bank. So just go. >> Yeah. >> Yeah. So you can imagine so no one will believe you. No one will trust you because you're cyber security to hack to hack. Then of course now for the business wise >> yes >> they don't uh some of them they don't know most of them they don't know about cyber security a few that that know cyber security issues they ignore because of budget constraints. So uh that one is also another challenge thatmemes now for the small >> medium enterprises. >> Yes, >> that's the challenge that they facing. They don't know but if they know they ignore because of budget, >> right? Uh maybe you can also deep dive into cuz we are now into the hacking part of it. Are there like good hackers? Somebody mentioned white hackers. Off the air you were telling me there's white and there's a gray and for me I had tried to say maybe there's black hackers too but then we summarize it with offensive and defensive hacking. Yeah, paint us a picture of what that entails into the world of hacking. >> White white hat hacker is a good one. >> This guy will come, you hire him, he scans the websites, the systems, he tries to identify security gaps and fix. >> Mhm. >> Blackart black >> is now the offensive one. The one who comes tries to interfere with the system tries to gain unauthorized access into the system. >> Yeah. >> Then at the end of the day money will be lost. >> Then we have the gray is in between depending on situation depending on condition um offensive or defensive. Now when we talk of offensive hacking >> is that type of hacking. >> Yes. >> I come to destroy systems. I come to steal some data from the system some information then of course defensive now we are coming there to protect the systems from this other type of hackers >> right I believe if you've not understood say yes or no p comment section and also we asking you what are some of the most common online scams as we pivot with this conversation like for example when a breach occurs and upin point last year when hackers infiltrated a citizen uh ministry of defense health state house was even the And they even demanded up to was it 41 million Kenya shillings and that was in bitcoin >> for institutions like government websites where citizens flock in all the time they clock in to you know process the visa a citizen birth certificate is there your passport etc. What would you recommend in terms of security measure and safety that should ensure that some of these hackers are kept completely at bay? And then also if you were to explain what could have possibly happened that they infiltrated the president's website, defested it and even demanded ransom. That's crazy and wild. Yeah. Please paint to us a picture of that. Now um first of all let me echo what the government is doing cuz in these public institutions most of them uh there's that I've seen some improvements in terms in terms of security and don't tell me when it was hacked no even before now and again as a country uh uh some few months ago we were at Safari Park Hotel coming up with our cyber security framework to work for the country those are good for has a very perfect improvement. What should they do? Um, look at this employee as a human being. >> Don't treat this person as a machine. >> We are securing the servers. We are securing the systems. They perfectly secured. But the person who is operating these systems >> is not secured. >> You understand the economic pressure in Kenya nowadays. Almost everyone is under stress, under pressure. So because of that alone, >> these guys are vulnerable. They're the one who are who are operating these secured systems, they're the one who are coming up with those strong passwords, but just a click of a button, they reveal everything to to the hackers. So look at this employee. Do not treat him or her >> as a as a machine, >> right? >> Treat him as a human being. Remember he has emotions, he has >> heust. So all these things might be used against the government. >> Right. Yeah. >> Absolutely. And these are humans once again. All right. As we take a break on that note, we are asking you on our post and engagement question. What online scams have you ever fallen for? What happened? Also, what is your wildest online scam story? Please feel free to share with us on the hashtag which is power talk to show at y254 channel and at brian circle101. When we come back, we'll also be asking our guest, is it good to keep on logging into different sites? You're trying to research, do an assignment, cyber email. Is it a good habit? Yes. We'll find out from our guest in just a bit. Let's let's take a break. See you on the other side. All right, welcome back. Thank you for staying with us. You're still watching part of TV show. Now, before we went on a break with my guest Christopher Hayier, we had asked you is it a good thing by the way to keep on logging into different devices in the name of I'm doing an assignment. But I believe it's very common as well to students, you know, assignment, send this email or respond to this and that. But then you realize you're keeping a trail as well, a trunk. You log into this computer, you log out tomorrow. And let me uh get it back to you. Uh Christopher, is it a good habit? And maybe what are the dangers? Cuz this is a student maybe on a laptop. They only have a smartphone, but they have to do this assignment. So tomorrow they'll be at a cyber cafe in town. Next they loging in Karin. Next they logging at the university institution. And what are the dangers of keeping such a trail especially if you're navigating online in the cyber space? >> Uh it's not recommended to keep on logging on different devices. um um when you're doing your online stuff for this case uh Brad I want to ask you something about email when you sign up for different portals or accounts like Tik Tok like Facebook like even help like even all other sort of accounts >> email address >> so email address now becomes the primary form of security if it's if it is compro compromised. You can imagine the attack surface. Almost all your accounts will be gone. So if I have your email address, I'm able to gain an authorized access in all your accounts including Facebook. >> Those that I don't know passwords, I'm able to reset the passwords. >> I'm also able to get your saved passwords. >> Yeah. >> In your Google account just using your email address. I'm also able to do what? To get your personal pictures upload Google photos. So I'm able to do what? to get copies of all those pictures in my phone. Now, with all this information, I'm also I'm also I'm also able to get your timelines in terms of so at the end of the day, I have your profile of how you operate, where you go, the friends that you have because I'll be able to get your phone contact, phone book, y I'll be able to get it. So, if I have almost everything about you, what do you think I can do? can do almost every sort of hacking activities on you. So it's not recommended to keep on logging here and there and there. >> Yeah. And we having a conversation with a friend and there's one of one of them who is in the text space who was saying you're not even supposed to have conversations about passwords and your private you know identification you know information etc. Maybe if you are to advise u a person who's watching right now in terms of passwords where maybe they're not easily hacked or it's difficult for you to piece up or guess cuz I can only imagine somebody who has a password like 1 2 3 4 5 cuz at first when passwords came you only wanted a password that you could you could easily remember. Yes. Or memorize. So what would you educate this person on a good strong password for Instagram, Tik Tok, Facebook etc. Twitch, YouTube, where nobody can easily guess or a hacker cannot try to piece up and I'd be shocked if somebody would imagine your password and guess it and successfully log in. That would be stunning. >> Now the the strongest uh the strongest password uh should be a combination of um uppercase lower case numbers and special characters. >> Mhm. >> And it should be long enough like 12 digits. >> 12 characters. How will you remember? How do you how do you remember a 12digit password >> and they should be unique from one account to another account say that if I get your password for Facebook >> Instagram yeah >> I should not be able to log into your Instagram account >> so they should also be unique from one account to another account >> with all these social media platforms Tik Tok YouTube Facebook Twitch Insta >> now that is where the password managers comes in >> okay >> yeah you can use now password managers be able to generate you strong passwords. >> They're able to store those passwords for you. Then you can simply retrieve every time you want to login in a continue with this. But there's a danger with that. >> Once this password manager is compromised, all your accounts will be compromised. >> Yeah. >> So the moment you you decide that I want to use a password manager like the Google password manager, >> then be ready to protect that account like a new house. >> Yeah. >> Yeah. So meaning that whenever you log if you're in the public service vehicle hide it cover it do it under the blanket >> not really >> to protect it like a new house I meant this ensure that that Google account the password to me is very unique ensure that you have enabled two factor authentication now for this case don't use the normal SMS uh authentication >> use the the no the authenticator app. >> Oh, the authenticator app. What if it also gets hacked? Cuz now hackers are passing through everywhere. >> Now that one is only possible if I have access to your phone >> physically. Now the device >> not not just physically, >> not just physically but even through connections or networking. >> Now for that case now to ensure that this one is safe. >> Mhm. be aware of different forms of social engineering. That's like the fishing that link will give that person access to your device Facebooks by opening that picture I'm able to take over your phone with just a selfie. >> Yeah. >> Right. So you'd advise strong passwords uh to a fair that is two factor authentification. >> Yeah. How many digits? 12 plus >> at least 12. Yeah, >> 12 is too much. >> To remember, >> of course, you can memorize a 12. >> If you if you can't remember >> a 12digit password, >> you can use the the password managers for that case. >> Yeah. What about somebody who's using an Instagram password to login into Facebook even though all of them are meta products, but they're using it even to log into Tik Tok, LinkedIn. Is that a danger? Is it dangerous? >> Of course, it is. If I get that password, >> maybe there is a data breach in one of the portals or the systems that you're using. >> Okay, >> there's a data breach as a hacker. I have your password for that particular account cuz I'll try accessing different accounts using that password. You see the attack surface. >> Yeah. >> So the damage will be spread all over. >> Right. And maybe let's deep dive as well like are there patterns that a hacker is likely to carry in terms of their character that you can trail that you can let's say you can keep up and make record and know I think you had explained it earlier on but maybe what is the character of a hacker in terms of uh you like when they hacked into it I don't know what they did but nothing happened. Yeah, >> even the president's site etc. What is what are the characteristics of this person who is this devil who is demanding 41 million Kenya shillings as a ransom? >> Can you tell that the tellt tell signs there's a person here? >> Yes, of course. The first thing that any hacker will do when he logs in to any system is to try to maintain access. >> Maintaining access it means that I'll have to keep you out of this. Yes. So, I kick you out of this house. Then I'll try to change the recovery methods. You're using your phone, your email address as a recovery, and I still don't have access to your mobile phone. I don't have access to your email address. So, I have to change for me now to stay here. Otherwise, if I maintain those recovery accounts, >> what will happen? So those are the things out of the system the recovery details will be changed and even some of your data in >> yeah all sort of things will happen even the name might change. Yeah. And I want us to deep dive now into your uh your profile and how you guys are helping this in terms of digital forensics policies and law. For example, how uh does the data protection act of 2019 come to play for companies in breach of of of data and privacy? And also maybe for a company uh in terms of them securing their data in a way that it's only accessible to mandated persons that are professionally allowed to handle this data ethically. How does it run that part? >> Now um data protection act of 2019 brought what we call the office of data protection commissioner the ODPC. ODPC oversees how businesses handle customer data. Right >> now in businesses we have two two two people here two parties in fact three three parties. >> We have the data controller we have the data processor and we have the data subject. >> Data subject Brian is me and you. We are the data owners. So we become the data subject. The data processor is the data controller is the one who determines which kind of data should be collected from the data subject. Then we have the data processor who now processes this data on behalf of this data controller or of this business. A perfect example >> is that a third party? >> Yes. In most cases it is a perfect example. >> Mhm. >> I have a company, I have staff, I have their data, their payroll data, but I rely on another company to prepare the payroll and even pay them. >> Is that even secure and safe? Now let's go back to the data protection what he talks about such >> right please go ahead >> because you are now engaging another third party >> to process some data >> on your behalf >> you need to have what what we call the data processing agreement >> between the two of you >> such that if something happens the ODPC would not come for this third party >> it will come for you as the data controller because you are the primary the primary legal person who is collecting who is determining which kind of data to be collected from your customers. So not come for this person but it will come it will come for to you who collected this information so that my business can continue >> I'm thinking of uh uh is it the the health records at at let's say NHF and SH and NSF way back I'm also looking at IDs yeah and the ecizitizen platforms so maybe how's the back end of that and how is it working If you are to explain, >> of course the government API, if you're asking about >> how they connect like ID number and extract some information from system to lo into your citizen, you need your ID number. >> Yes, true. Where where are they getting this information? So there is what we call the government API. You going to all this sort of information from the birth certificate on a register 18 years. you are given ID number. This ID number is connected to K. This K pin is this this this this. So at the end of the day >> if you have now like um a system most in most cases in government systems that needs this information maybe to verify or do this and this they usually we usually have what you call the government API. So once you >> what does it mean by the way in full? Somebody's like what is API? API is application programming interface that helps this server to fetch some information or data from another server. >> Right. >> Yeah. >> So you in a letter information from this server you verify then you query all those sort of things. >> Yeah. But somebody will also ask why are government websites just prone to hacking? Yes. They have the data that's well needed. There was a time there was a debate on I think it was a healthcare partnership program between the US and Kenya and Marco Robbo sounded off on it. He said you know we've had this you know in fact it's a it's a five year or a 10 year plan but again at some point they mentioned they needed Kenya's healthcare data records you know and somebody said oh we are just sold d is a whole banter on data and privacy but still back to the question why are government sites prone to hackers? Now you need to understand one thing Brian I'm also from the government sector >> um and I've seen this as as a challenge you see today we can identify that there is a serious gap a security gap that we need to fixing this gap we need some money and money maybe you're going to procure a solution this procuring a solution is now where the problem is we now go back to procurement that we need to have a budget this budget need to do this and this is step step procurement. So with all this time being wasted in procurement and we still have this gap in so there are hacker somewhere who has been monitoring us will do what will take advantage of this gap and exploit the system. >> Yeah. So that's where the problem is. >> Decisions making in government sectors is not that as quick as decision making in private sectors. >> Yeah. >> Come private or system. What do we need? We need to procure a new firewall. Do we have money for that? >> Yeah. >> Because decisions there is quicker faster quick compared to government. >> It's a process and >> and of course these government systems again they are interconnected. So if one interfered with chances that these other systems interfered with >> quite high >> there was even a debate I think was it in Senate where they were questioning why was uh the data of this uh government service being held by a third party I don't know what entity was it it's very common among genz conversations where they're saying bon third party it's it's escaping my mind anyways here and there was huge debate on that too as well but let's also look at the cyber crimes act of 20 uh is it 2018 there's a 2018 one >> and and then now the I think it's the computer misuse and cyber crimes act of 2018 maybe how does it impact now >> uh navigating online and how you guys do investigation forensic investigations and analysis >> there's a problem some some 15 years ago >> all right >> where I could hack your system I take money from your system or just interfere with how your system works But you don't take me anywhere. But now with this cyber crime act in a letter issues cyber crime in a tries to do what? To interfere with the system. >> Yeah. >> In fact in a define what cyber crime is all about. evidence connecting this person to this particular attack >> then this is the repercussion and these are the consequences in terms of legal discharge some basis so they had to formulate a policy >> yes they had to come up with a policy the same way with the data protection to mishandle customer data. >> Someone is just calling you 100 times just sending you some endless messages. What are you supposed to do? >> Right? >> There was no act for that. >> So in terms of legal that one was a plus because today I try to hack a system I interfere with the system functionality there's evidence connecting me to that particular action. >> Right. >> Yeah. >> Maybe in the same breath there's an interesting question here. Maybe for example when you secure evidence for law enforcement what makes digital evidence legally admissible in court cuz that's when now person has escalated it and also maybe you can take it even to when people are trending hashtags malicious hashtags uh sometimes smear campaigns etc or even bullying cyber bullying too it's part of that as well so how do you uh secure and make digital evidence legally admissible in court have you ever found yourself in incidences where you know a client or a person is escalating it to the courts of law. >> H I was once in such nilend could present as an expert. Okay. >> I was hired as an expert to do some to collect some evidence from CCTV and I went to to present >> brand. Um what if I tell you now that you might have screenshot the WhatsApp you present them to the court of law like evidence. Yeah. >> What if I tell you that? >> Mhm. >> Unless it is a serious criminal case. A serious criminal case. >> Yeah. WhatsApp communication. >> Yeah. Why? Because the clear boundary between privacy >> Mhm. >> evidence at the same time but these are these are private what conversation we are having with you. >> Yes. >> It will not be treated as an evidence. >> So maybe what makes it now admissible? >> Number one, when there is a court order, >> right? Now bring those evidence and as you bring those screenshots do not delete the original conversation evidence. So you you you need to have what >> the original evidence. Now if it is now for the server for the business spaces do not give us evidence the opensource softwares >> without any license. No this evidence the tools that you have used to extract this evidence commercial tools you paying for a license otherwise these premium tools that you use the open source >> may not be accepted. >> Right. Well, let's pause on it as we uh take feedback. And we are asking you on our question, what online scum have you ever fallen for? Yes. What online scum have you ever fallen for? And we also ask you to tell us your wildest hacking stories. And there's interesting feedback coming through. Uh there's Julius Rea tuned in from Ner Town. Shout out to you. And then there's minor Steven buying Facebook products. Is it a thing Chris with buying Facebook products? >> Yeah, Kenya, we are still not yet there. Uh-huh. >> In terms of online marketing, >> right, >> we are not yet there. >> There's trust issues. There's stress all over. There's financial pressure all over. So, Kenyans, other funny Kenyans will take advantage of this online stuff then get some money. >> Okay. Uh, next um we also have Sifuna Brian. Oh, interesting. you know, dating Amazu from Germany, paying delivery fee for gifts where this happens a lot as well where you somebody text you and they tell you, you know what, I just spotted your profile from the US and here we are. Yeah. >> At that point, Brian, >> the scammers are exploiting emotional, >> right? >> The loneliness in you. Maybe you're lonely. You want someone then boom. So they've noticed maybe you're on a dating >> because they have they have so they'll exploit that in you because you're a human being. So that emotional aspect you want to talk to someone, you want to chat with someone, you want to call someone, they come girlfriends or boyfriends. >> Yes. And then second last but not least 2013. Okay. Interesting. And then Palmer buying products through Facebook. nil Joshua and I think you've reacted to that too as well and I want us to close this conversation to and I understand you have a book but you'll tell us uh uh the story behind the book as well as you close it up I want you to maybe explain to us what what is the major challenge is there like a skill gump uh issue in the cyber security space because I I interviewed I think it's on a different show anyways he was telling me cyber security experts are not many in Kenya so they're calling on more to come on board in terms of training skilling and even upskilling Would you say that's the main challenge as we get into the book too as well? >> Yes, Brian I'll say that's the main challenge. We have so many cyber security students can say so even those who call themselves professionals but how many can come near KBC coini idea >> there are few so that's a that's a a major challenge we are having we don't have experienced cyber security professionals in Kenya >> and where is this a problem coming from because we don't have again serious institutions that are teaching serious cyber security. Most of these you sto institutions that are teaching cyber security. That's why I told you as we began the show that cyber psychology >> and human hacking. It's a new concept. >> It's a new concept foreign institutions are there teaching that >> right. Absolutely. So we need more on board. Talk about your book shortly as we exit and how they can get to purchase it. A short story line behind it. Understand you have a series of them too as well. Thank you brand. These are the the book is the error. >> The teacher I never wanted. >> The error the teacher I never wanted. Interesting. >> The book basically talks about the pain the mistakes that we do in life and the unexpected lessons that we get from those pain. >> It start with telling us the beginning of errors where the errors began. The things we used to see our fathers doing, our mothers doing, our elder brothers and sisters doing, our uncles doing and we learn from them. Because when a child is born this child is empty by doing so and at the right time the appointed time the child will do the same things that the father >> replicate. Yes. >> So it's generational patterns. So at the end of the day we make errors. We think we are doing the right thing but we make errors. But these errors they give us lessons. They give us another another wisdom, >> okay, >> on how we navigate. >> So if so, if a person is going to buy I'm being told you're on a timeout button. We're just about to exit. So if how can they buy the book? Where is it and how will it be of help in 10 seconds? Look at them in the camera. >> The book is is on Nura Jun Kilimon. To read it, you can visit my website www.hayer.com. >> Yeah. Does it have a number too? >> Yes. Okay. >> 0799 874578. >> Absolutely. I think they they'll piece up all that information and get to buy this book. I hope that's my copy to it. We'll talk the air. >> Thank you so much. All right. >> All right. Thank you so much Christopher Hayier for being here. He's a coordinator at Kenya Cyber Security and Forensics Association for your incredible and valuable uh insights in this conversation. We also want to thank you for watching us from 7 to right about now. If you missed anything, I promise you'll find it on YouTube at Y244 channel. And we continue the conversation as we go off on the hashtag which is power talk power talk show, not power talk TV show. A man at Brans 101. Thank you for watching. See you next time right here on Power Talk.