Video summary
The Power Talk Show episode featuring host Brian Squa and Christopher Hayer delves into the critical intersection of psychology and cybersecurity, emphasizing that modern hacking often exploits human behavior rather than just technical flaws. The discussion highlights how individuals in Kenya frequently overshare sensitive personal details on social media, such as locations and family information, which allows attackers to build psychological profiles for targeted attacks. This vulnerability is compounded by sophisticated social engineering tactics like phishing, where scammers induce fear or urgency through fake messages about frozen accounts or fabricated windfalls designed to trigger emotional responses that bypass logical thinking. Furthermore, the rise of AI-powered threats has made these attacks more insidious, with voice cloning and deepfakes enabling criminals to trick employees into transferring large sums of money using forged audio notes from their bosses.
To combat these evolving dangers, experts advocate for a security approach that treats employees as humans with emotions rather than machines, promoting a bottom-up awareness model where individuals pause before reacting to urgent messages and verify sources rigorously. Practical defenses include using strong, unique passwords of at least twelve characters, enabling two-factor authentication via authenticator apps instead of SMS, and utilizing password managers to secure credentials. Organizations must also be vigilant for indicators of compromise such as unexpected notifications, unknown active sessions, deleted files, and server logs showing communication with suspicious IP addresses, requiring them to notify the Office of the Data Protection Commissioner within seventy-two hours of any breach. The legal landscape has shifted significantly with the Cyber Crime Act of 2018, which now legally defines and penalizes interference with system functionality, while also establishing strict rules for digital evidence admissibility in court that require original data preservation rather than mere screenshots.
Beyond individual and organizational measures, the conversation addresses systemic challenges such as government vulnerabilities caused by slow procurement processes and budget constraints that delay the acquisition of essential security solutions like firewalls. Under the Data Protection Act of 2019, primary data collectors remain legally responsible even when third parties process information, reinforcing the need for robust governance structures. A major hurdle identified is the severe shortage of experienced cybersecurity professionals in Kenya due to a lack of local institutions teaching advanced concepts like cyber psychology and human hacking. To bridge this gap and help individuals navigate generational patterns of mistakes, Christopher Hayer promotes his book, *The Error: The Teacher I Never Wanted*, which offers wisdom gained from errors and is available for purchase through his website or phone number, serving as a resource for understanding the complex dynamics of online safety.
Read the full video transcript
All right. Absolutely. Good evening to
you. Thank you so much for joining us
right here on Power Talk Show. My good
name is Brian Squa and in just a bit
we'll be posting our question of the
day. So we're inviting your thoughts and
your feedback on it. Now tonight we
delve into m human human hacking. Now in
the baming Kenyan digital landscape, a
click, a like, a share or even swiping
could cost you just more than data. With
Jenzis being the first generation to
ever fully live online, they're
susceptible and even prone to things
like, you know, hacking, threats, leaks,
and even intense surveillance. with my
guest joining me live in studio is going
to help me unpack how some of these
cyber attacks and threats hitting your
mobile phone and device are redefining
and shaping rules and rewriting laws of
online safety. And I've been engaging
with Christopher Hayer. He's a
coordinator at Kenya Cyber Security and
Forensics Association. Great to have
you. Good evening.
>> Thank you, sir.
>> Right. So, let's let's get to hear from
you first and your profile a little bit.
Maybe you can start off from what are
some of the annoying online habits. I'm
using annoying so that we just pinpoint
exactly but maybe they're concerning
also in a good way or a bad way about
Kenyans and how they navigate through
the ever booming digital landscape in
Kenya.
>> Um thank you Brad for for this
opportunity. Now one thing that annoys
me as a cyber security practitioner is
that Kenyans we tend to overshare.
You're going to Mombasa you post online.
You are taking your kids to school you
post online and even you tell us your
their details. Now you're doing this.
You don't know that as a hacker I'm able
to extract location from these pictures
that you're sharing with me. As a
hacker, I just need um 3 seconds of your
voice in whichever maybe it could be I
can get it from a video
>> to to perform some other types of
attacks based on on um on on on your
voice. So they tend to overshare and I
think by oversharing that information
that data you giving a hacker a script
about your life. So I'm going to use
this information to do what? To perform
some kind of attack on you.
>> So what would you recommend though?
Should they limit what they share? Cuz
when you look at a person who is a
content creator, Jenzi who's an
influencer, they're all about posting
updates. I'm at this club. Come, let's
have fun. I'm going to do this event.
I'm going to this TV interview like
Chris. Aren't you not informing your
followers and your fans of you know your
journey and what you're doing? And why
is it dangerous then?
>> Um Brian, we need to have a clear
boundary between content creation and
personal data. Um I'm not saying that
you should not uh share what you're
doing but we must have a clear boundary
between what you are sharing and your
own safety. Like for instance, um maybe
I have three kids. I'm going to post
their their their full names on social
media. I'm going to post my my wife
details on social media. I'm going to
post where I work, the office that I sit
on social media. You see, these are
personal data. So we need to have a
clear boundary of what we post online
in terms of content creation and also we
also need to have a a clear boundary of
um of of of personal safety. Now what is
the danger of all these things? Now you
share your personal data on social
media. You're basically giving a hacker
a script about your life.
>> I know where you live. I know where you
work. I know the kids that you have. I
know everything about you.
information.
I simply need to do what? To understand
something about you to get some
information about you to to come up with
a clear profile about the target. Then I
come up with a psych psychological
weapon that that I I will use against
you. So you see the the the correct
psychological weapon against you at the
right time to make you a victim
>> right
>> of any type of attack.
>> So let me ask you before you lose your
train of thought. What should you not
post and what should you post? Cuz you
know those are those are restrictions
when you look at it deeply. It's like
you're redefining how somebody should
operate using their social media
platforms. So, are there limits to what
specific stuff you should share online
and what you should not? What would you
pinpoint exactly of what you should
share and what you shouldn't
specifically for an individual?
>> Um, you can share general data, general
information. This guy is Chris. Chris is
a cyber security engineer. You can share
that. But you should not share your
personal information. Like for instance,
my ID number. Why should I share my ID
number on social media?
>> Are there people that share ID numbers?
Yes, they do. They take a selfie of
screenshot of their ID
the voters card.
>> They share on the on the internet so
that other people can see. Oh.
>> Yes. Exactly. So we we should not share
personal data. The year of birth. Why
should you share your your date of
birth?
>> These are the things that as a hack I
need to come up with a profile about
you.
>> Yeah.
>> Right. uh and maybe would you say is
this what drove you into this uh
profession because you are the
coordinator at cyber and at Kenya cyber
security and forensics association. So
maybe what makes your profile and the
passion that drives you to be passionate
about this conversation in the cyber
security space.
>> I like solving challenges. I like um
dealing with for me difficult things.
>> Yeah. Now I realize that cyber security
is more of hacking play around with a
computer system to security to identify
those gaps. So that's what I love. So
the fact that it's challenging it needs
some critical thinking is what drove me
into these things. I didn't want to do
something that is boring. Come on.
>> Yeah. Right. Of course. But you know
being a tech when you're a cyber
security expert it means your your your
personality as well could be more
laidback. your focus like most techies
are actually nonchalant laidback and
just you know less words they're more
into tech stuff researching and all that
yeah so I believe you are suitable for
this too and also maybe let's get to
start of understanding what are some of
the common cyber attacks that happened
to a daily average Kenyan you know
because we are all about you know social
media and if you look at Jensen even
when you look at the mandos and
everything that happened it was all
online they never met in person they
only met during protest and
demonstration So how do we debunk that
and make it you know a conversation that
should constantly continue to be there
even though we are trying to reshape the
rules of navigating online but it's a
space that everyone should be there but
with safety. So maybe what are some of
the common threats?
>> Uh the common threats the I want to
answer your question. It's it's um it's
more social engineering attacks where
social engineering attacks involves
manipulating people into revealing some
sensitive information that me as a
hacker I'll use them against them.
>> Yeah. So and the most common example in
Kenya is fishing attack where I draft
you a message I'm telling you hi Brian
this and this I'm from the bank your
account has been frozen click here if
you think this is a problem to do what
>> to unlock or to do so so because of that
message in that message there is fear
already in that message your account has
been frozen then click here before 2
hours the aspect of urgency now coming
in what happens when you are under fear
and urgency logical thinking normally
stops once logical
thinging stops. You don't verify any of
these information. So you went you will
go ahead click those funny funny links
then at the end of the day what will
happen you lose money. Like today I was
solving a particular case
>> where
>> someone
um pretending to be from safar
>> calls someone that I know.
>> Mhm. Uh this person is telling this this
now someone that I know that um we are
calling you from Safariccom Empessa. We
realize that your account has done this
and this. So we are supposed to verify
some information about you for us to do
what to unlock.
>> This person does not know about the
online scams. So he goes ahead click
those buttons. He has been instructed to
do so. Then at the end of the day you
see
>> there there was money transfer from this
account to the
>> Yes. to the scammers. So the fishing
attack is the most common form of of
hack that is that we are experiencing as
a country,
>> right?
>> Uh for somebody who's watching this
conversation and maybe they've already
clear cuz some of those links are very
enticing actually. They'll be like click
for good luck. You just won 1 million uh
USD. Um somebody and so from New York
City I sent a container. Click on this
link. And then it ends up even you know
creating a site and you end up creating
a site. you log in and eventually end up
being logged out of you know your for
example if it's your mobile device or
your computer etc. So for somebody who's
watching this conversation and they want
to understand some of the safety
measures that they can employ online so
that you know they ensure that there's
safety whenever anything happens. What
would you advise them and what should
they do individually and then
institutional wise but maybe we can get
to some of the cyber attacks that are
prone to institutions. Let's finish up
with individuals mobile phone computer
etc. What would you advise them
>> now? Um Brian before we understand how
to tackle those kind of attacks, we need
to understand what normally happens.
Yes.
>> Like for instance, the the the best
example used about you have received a
container from this and this it has this
and this. You see human beings you are
wired to receive.
>> Anytime Brian you receive something, you
become happy.
>> When you're happy, what happens? Your
body produces dopamine hormone. Dopamine
hormone is the happy hormone. Happy
hormone that makes us feel excited.
>> Once that hormone is released in the
body, logical thinking
>> escapes, travels.
>> Yes. Once that one is gone, will you
verify?
>> Yeah.
>> You will not verify any of this
information.
>> You have been told that I've sent a
container worthy 10 million. You go
ahead and do what?
>> And and and and receive. So the best way
now to tackle this, we understand, we
accept that first of all, we are human
beings. We have emotions, we make
decisions, we trust. So the first thing
that um uh that we have to do number one
is first of all to pause. Whenever you
receive a message, a call, you pause,
you you pause, then you think about it.
Ask yourself what are some of the
psychological emotions is this message
trying to trigger in me?
>> Right?
>> They'll trigger happiness in you.
they'll trigger some stress in you,
pressure in you, some aspect of urgency
in you. So as you pause and ask yourself
about this um this question, what are
some of the
>> emotions that got triggered by this
message? Now you move to the next phase.
>> The next phase is now to verify.
>> Now you verify if this information is
genuine. If this email is coming from
the real IT support, if this email or or
if this call is coming from the real
bank. So you do what? You verify this
information. So now verifying continue.
If it's clicking, it's upon you.
>> Yeah.
>> But click only once you are verified.
>> So that would refer to an individual
profile or an institution.
>> Both in this case both. For the
organizations you ask about the common
attacks that happens in an organization.
Still we are coming back to human Brian
the the in cyber security the weakest
link is not technology it's human being
operating these computers so even the
hackers who want to hack a particular
organization company they not go for
those servers cuz they know those
servers are very much secured they'll
come for this admin who is a human being
>> yeah so
>> and now in a in in um in an organization
setup there's a problem that we normally
we normally do in form of we train
people We create awareness but we're
treating these people as machines.
>> Yeah,
>> that's the problem.
>> Once you treat once you treat this stuff
as a machine, it means that you're
giving him or her a manual to follow,
create a strong password, but you're
forgetting this is a person, this is a
human being who has emotions, who make
decisions, who is under stress, who is
under pressure. So if there is an attack
that will come to your organization, it
will not for me as a hack, I'll not
focus on that server. I'll focus on this
admin who is a human being. So at the
end of the day
>> so solution to that how do we do
>> um we adopt the bottom up model for
security awareness in an organization.
What do I mean
>> organizations like no before
>> they they they deploy this model the
know the bottom up the bottom up.
look at that stuff, treat him or her as
a human being,
>> get to understand what he or she knows
about cyber security, then build from
that.
>> Absolutely.
>> That is now the bottom up model,
>> right?
>> And maybe uh in just a bit uh you'll
tell us so what exactly is being is
hacking. Yeah, if you to explain it in
simple term for somebody who's just
joining in in the conversation. But
online, we are asking you what online
scum have you ever fallen for? Please
let us know. We've just talked about
fishing. Clicking on a link, you've won
a container. Oh, click this. You have 1
million USD that's on the way, but it
has just been deposited in your bank. I
think the common one is somebody calls
you and tells you uh they they first of
all, they send you an Empessa message
and it it has hidden the number and the
amount, right? And they're not telling
you where that Empessa message is from,
but also it's not from Empessa, right?
So, please, what other forms of hacking
or scams have you endured online? And
the hashtag is power talkshu right 24
channel at brand circle101 basically as
we pivot before we get to um how modern
day hacking looks like for an
institution and we'll get to so many
other as well that have happened in the
country uh what is hacking in general if
you to explain it to Alana who's just
tuned in right now.
>> Hacking um is actually gaining
unauthorized access into a particular
system. It could be an office. It could
be a room. It could be a computer
unauthorized access meaning you are not
authorized you're not permitted to gain
access to do something in that
particular computer. So once you have
that unauthorized access into the system
then you can steal some information or
some data then you're going now to use
this data that you have stolen from this
computer to perform some other types of
now
>> malicious activities like maybe steal
money.
>> I have the information I can go ahead
and do the
>> data. Yeah. And you know we live in a
world of data renting. I think with big
tech there this there's one of the tech
influencers who was explaining that
we're heading to a cyber world where
institutions will be able to buy data
from other countries and use it as
statistics. And somebody brought in a
conversation on health records you know
and the funding etc. I found it to be
really interesting. But let's deep dive
into how does modern hacking look like
today in this world we are living in
right now. Nowadays we are using AI in
almost everything. So the type of of
hacking activities that normally takes
place. We don't nowadays rely on
traditional methods of hacking like I
need to come up with to come here with
my computer connect it to this and this
run these tools try this and this. No
almost um every form of hacking nowadays
it's AI powered. you find that this is
connected to a particular like the one I
was telling you the voice cloning where
I simply need 3 seconds of your voice
then I can generate
>> um hours of your voice maybe
giving out instructions just need your
voice for 3 seconds then I can come up
with that um with that clip
>> another another example is now the
fishing that you you talked about AI now
can generate those fishing links those
fishing males
within seconds you just give it a prompt
then you have a fishing a fishing email
>> yes
>> on on on the other side
>> again uh for the defensive side we're
also using AI now to do what to protect
these systems that's why he says that
now the modern form of hacking does not
focus on systems we're now focusing on
human being
>> so you're trying to like impersonate or
create an image of this person and even
use it to you know escalate other you
know hacking activities.
>> Yes. Exactly. Like let me give you an
example of the the notorious Facebook
hack. You realize that this account has
been compromised. This guy sends you a
link. Brian I saw you in this video.
Click to view. You see by sending you
that um that by sending you that link
telling you that I'm video click here to
view. There is that curiosity in you.
because
so systems are improving in terms of
security but human beings we still human
we still have emotions we still making
decisions you're still trusting so that
is now what the hackers are using AI to
exploit
>> yeah for a person who smelling a rat and
by that I mean trying to be suspicious
that you know what I feel like somebody
accessed this server and manipulated or
added something or adjusted something or
maybe there's a bug or infiltration of
some sorts cuz you know virus etc. Are
there like telltale signs or digital
footprints that hackers leave or trail
for a person maybe who's not who is not
a cyber security expert like you are
they can tell there's a possibility
that's why I said smelling a rat there's
a possibility somebody logged in or was
here and they adjusted stuff what are
they what are the cultural signs that
your system your computer your mobile
phone your accounts has been infiltrated
or attacked
>> of course uh those are what we call the
indicators of compromise that someone
was here. Yes. I'm not sure but someone
I suspect someone was here. For
instance, if it's a phone, you'll see
maybe some messages
without you knowing. Then you will get
some notifications. For this case, maybe
it's an email
notific.
The same thing with Facebook. They'll
tell you that
you're active in this device at a
particular location. So at the end of
the day
those
indicators
>> for business setup of course the servers
it has what we call the logs. So when
you collect these logs together
>> there is a a unique IP address IP
address that you even don't know a
domain name maybe that you even don't
know and you realize that this computer
was communicating with another computer
that even don't know where it exists and
of course some data has been deleted
manipulated or even transferred between
your computer or your server to the
remote machine then that one is an
indicator of compromise. What are you
supposed to do? M will be the next
question.
>> Yeah, maybe
>> for the case of business, for the case
of business and you realize that there
has been a data breach cuz once the data
>> has been transferred to another party
that is not associated with that
organization,
>> then that one is a data breach. You have
to notify the OPC within 72 hours and
all the stakeholders.
>> Yeah. And I want us now that you
mentioned AI and data for example now
with artificial intelligence how are
hackers using it to extort Kenyans now
with the voice cloning are there like
maybe stories wild stories that you've
heard in the cyber security space in
terms of you guys doing investigations
etc that you know hackers are using AI
to benefit from Kenyans without their
consent. I've dealt with uh some even
last week the one for AI cloning
>> where an employee walks in the office.
It is a Monday morning. It is just after
weekend though hangover
>> fatigue. Mhm.
>> Yeah.
>> Right.
>> A message comes in. Hey Morin, transfer
some money to this account. I'm in a
meeting. I'll sign later.
Within few seconds, Moren receives now a
voice to confirm a voice note from the
boss
>> to confirm
>> and within few minutes
that business or that company had
already lost 700,000
transferred to the to a particular
account.
>> Yeah.
>> So he was now conducted to perform the
forensic
>> forensic analysis.
>> Yes. To assist them
>> to see them. So that is now the the the
weird story I've heard about it cuz upon
analyzing all these things we realized
that this voice note that came in was AI
generated.
>> Mhm. The message that came in was also a
fake. It was it was it was a form of a
screenshot.
Come and sign later,
>> right?
>> But that screenshot,
it was AIDated. So I was able to come up
with search with a story or I mean with
a report of all those things and
realized that everything there was AI
powered generated and that made the
company lose some good money.
>> Yeah. And maybe how does it affect now
investigative strategies and approach to
that cuz I'm sure an AI AI evidence can
it needs an expertise eye or panoramic
lens for you to spot it. uh how does it
affect further piecing up of uh investig
rather of evidence that leads to a
hypothesis that now will result to an
investigation if it's AI or
>> because we have been having challenges
doing investigations by the way because
the hackers are not stupid these guys
will use proxy these guys will use the
VPN so you cannot even establish that
these guys in Nairobi
>> you try to to to to perform forensics
>> right
>> towia
Roman in real sense these guys in
Kilimani here in Nairobi now with AI
again we still have that challenge
you're trying to look at this you're
trying to use this tool to do this and
this but those guys are smart enough
that at a point who want to feature
metadata of all those images
>> but now when you go further
>> this is an email they claim it came from
this particular person
>> at this time on this date
>> right
>> let's go now to the mail server do we
have such a log
>> right
>> we don't have so that what what does
that tell us this this fake image
generated
>> it's crucial to prove this and this
>> right
>> and maybe are there tools that you guys
use as a cyber forensic experts
>> yeah we have I'll just uh I just tell
you
one
>> the image eye
>> image eye
>> Mhm. that we use now to analyze and the
pictures. You have a picture, you upload
it there. It will give you the exact
location where it was taken, the exact
time where it was taken, the device that
was used to take this uh picture,
>> the phone
>> or the media or the mode of of transfer.
This image was transferred from this
point A to point B and among other
metadata information that you need,
>> right? Maybe would you say that that's
one of the biggest challenges that uh is
facing uh cyber security professionals
lack of adequate material or equipment
to let's say uh take after an
investigation that especially with
hacking and we are going to deep dive
into the recent hacks and defacing of
government sites etc. Would you say
that's one of like the major, you know,
weigh down in your operations as a
professional in the cyber security
world?
>> Um,
>> in Kenya specifically, US. Yes.
>> Number one, there's a there's a there's
a problem in Kenya. We don't have enough
institutions that are teaching cyber
security.
>> Cyber psychology and human hacking is a
new concept in cyber security. Not just
new, but it has been around for for
quite some time. Yeah. But in Kenya,
have you even heard have you ever heard
about cyber psychology? Even they ask
>> not yet.
>> Now if you have never heard about it,
how many institutions in Kenya do you
think they're teaching that?
>> Right. We having a conversation at least
right now they've gotten a glimpse of
it. Yeah,
>> there's none zero institution teaching
about cyber psychology and human
hacking. But now that is where you are
heading as a cyber security issues. They
all most of them are now revolving
around around cyber psychology and human
hacking. But we don't have any
institution that is teaching cyber
psychology. I know you ask me
I do research.
>> I'm a researcher. I do a lot of research
on cyber psychology and human hacking
cuz I know that is where we are in terms
of cyber security. Another challenge as
a security now personal challenge is
that people don't trust you.
>> Yes. But I can tell you that there's a
time I went to a bank then I was making
a phone call the security officer in
that bank.
Why? Because he believes that this a
hacker is here to hack our bank. So just
go.
>> Yeah.
>> Yeah. So you can imagine so no one will
believe you. No one will trust you
because you're cyber security
to hack to hack. Then of course now for
the business wise
>> yes
>> they don't uh some of them they don't
know most of them they don't know about
cyber security a few that that know
cyber security issues they ignore
because of budget constraints. So uh
that one is also another challenge
thatmemes now for the small
>> medium enterprises.
>> Yes,
>> that's the challenge that they facing.
They don't know but if they know they
ignore because of budget,
>> right? Uh maybe you can also deep dive
into cuz we are now into the hacking
part of it. Are there like good hackers?
Somebody mentioned white hackers. Off
the air you were telling me there's
white and there's a gray and for me I
had tried to say maybe there's black
hackers too but then we summarize it
with offensive and defensive hacking.
Yeah, paint us a picture of what that
entails into the world of hacking.
>> White white hat hacker is a good one.
>> This guy will come, you hire him, he
scans the websites, the systems, he
tries to identify security gaps and fix.
>> Mhm.
>> Blackart black
>> is now the offensive one. The one who
comes tries to interfere with the system
tries to gain unauthorized access into
the system.
>> Yeah.
>> Then at the end of the day money will be
lost.
>> Then we have the gray is in between
depending on situation depending on
condition
um offensive or defensive. Now when we
talk of offensive hacking
>> is that type of hacking.
>> Yes.
>> I come to destroy systems. I come to
steal some data from the system some
information then of course defensive now
we are coming there to protect the
systems from this other type of hackers
>> right I believe if you've not understood
say yes or no p comment section and also
we asking you what are some of the most
common online scams as we pivot with
this conversation like for example when
a breach occurs and upin point last year
when hackers infiltrated a citizen uh
ministry of defense health state house
was even the And they even demanded up
to was it 41 million Kenya shillings and
that was in bitcoin
>> for institutions like government
websites where citizens flock in all the
time they clock in to you know process
the visa a citizen birth certificate is
there your passport etc. What would you
recommend in terms of security measure
and safety that should ensure that some
of these hackers are kept completely at
bay? And then also if you were to
explain what could have possibly
happened that they infiltrated the
president's website, defested it and
even demanded ransom. That's crazy and
wild. Yeah. Please paint to us a picture
of that. Now um first of all let me echo
what the government is doing cuz in
these public institutions most of them
uh there's that I've seen some
improvements in terms in terms of
security and don't tell me when it was
hacked no even before now and again as a
country uh uh some few months ago we
were at Safari Park Hotel coming up with
our cyber security framework to work for
the country those are good for has a
very perfect improvement. What should
they do? Um,
look at this employee as a human being.
>> Don't treat this person as a machine.
>> We are securing the servers. We are
securing the systems. They perfectly
secured. But the person who is operating
these systems
>> is not secured.
>> You understand the economic pressure in
Kenya nowadays. Almost everyone is under
stress, under pressure. So because of
that alone,
>> these guys are vulnerable. They're the
one who are who are operating these
secured systems, they're the one who are
coming up with those strong passwords,
but just a click of a button, they
reveal everything to to the hackers. So
look at this employee. Do not treat him
or her
>> as a as a machine,
>> right?
>> Treat him as a human being. Remember he
has emotions, he has
>> heust.
So all these things might be used
against the government.
>> Right. Yeah.
>> Absolutely. And these are humans once
again. All right. As we take a break on
that note, we are asking you on our post
and engagement question. What online
scams have you ever fallen for? What
happened? Also, what is your wildest
online scam story? Please feel free to
share with us on the hashtag which is
power talk to show at y254 channel and
at brian circle101.
When we come back, we'll also be asking
our guest, is it good to keep on logging
into different sites? You're trying to
research, do an assignment, cyber email.
Is it a good habit? Yes. We'll find out
from our guest in just a bit. Let's
let's take a break. See you on the other
side.
All right, welcome back. Thank you for
staying with us. You're still watching
part of TV show. Now, before we went on
a break with my guest Christopher
Hayier, we had asked you is it a good
thing by the way to keep on logging into
different devices in the name of I'm
doing an assignment. But I believe it's
very common as well to students, you
know,
assignment, send this email or respond
to this and that. But then you realize
you're keeping a trail as well, a trunk.
You log into this computer, you log out
tomorrow. And let me uh get it back to
you. Uh Christopher, is it a good habit?
And maybe what are the dangers? Cuz this
is a student maybe on a laptop. They
only have a smartphone, but they have to
do this assignment. So tomorrow they'll
be at a cyber cafe in town. Next they
loging in Karin. Next they logging at
the university institution. And what are
the dangers of keeping such a trail
especially if you're navigating online
in the cyber space?
>> Uh it's not recommended to keep on
logging on different devices.
um
um when you're doing your online stuff
for this case uh Brad I want to ask you
something about email when you sign up
for different portals or accounts like
Tik Tok like Facebook like even help
like even all other sort of accounts
>> email address
>> so email address now becomes the primary
form of security if it's if it is compro
compromised. You can imagine the attack
surface. Almost all your accounts will
be gone. So if I have your email
address, I'm able to gain an authorized
access in all your accounts including
Facebook.
>> Those that I don't know passwords, I'm
able to reset the passwords.
>> I'm also able to get your saved
passwords.
>> Yeah.
>> In your Google account just using your
email address. I'm also able to do what?
To get your personal pictures upload
Google photos. So I'm able to do what?
to get copies of all those pictures in
my phone. Now, with all this
information, I'm also I'm also I'm also
able to get your timelines in terms of
so at the end of the day, I have your
profile of how you operate, where you
go, the friends that you have because
I'll be able to get your phone contact,
phone book, y I'll be able to get it.
So, if I have almost everything about
you, what do you think I can do? can do
almost every sort of hacking activities
on you. So it's not recommended to keep
on logging here and there and there.
>> Yeah. And we having a conversation with
a friend and there's one of one of them
who is in the text space who was saying
you're not even supposed to have
conversations about passwords and your
private you know identification you know
information etc. Maybe if you are to
advise u a person who's watching right
now in terms of passwords where maybe
they're not easily hacked or it's
difficult for you to piece up or guess
cuz I can only imagine somebody who has
a password like 1 2 3 4 5 cuz at first
when passwords came you only wanted a
password that you could you could easily
remember. Yes. Or memorize. So what
would you educate this person on a good
strong password for Instagram, Tik Tok,
Facebook etc. Twitch, YouTube, where
nobody can easily guess or a hacker
cannot try to piece up and I'd be
shocked if somebody would imagine your
password and guess it and successfully
log in. That would be stunning.
>> Now the the strongest uh the strongest
password uh should be a combination of
um uppercase lower case numbers and
special characters.
>> Mhm.
>> And it should be long enough like 12
digits.
>> 12 characters. How will you remember?
How do you how do you remember a 12digit
password
>> and they should be unique from one
account to another account say that if I
get your password for Facebook
>> Instagram yeah
>> I should not be able to log into your
Instagram account
>> so they should also be unique from one
account to another account
>> with all these social media platforms
Tik Tok YouTube Facebook Twitch Insta
>> now that is where the password managers
comes in
>> okay
>> yeah you can use now password managers
be able to generate you strong
passwords.
>> They're able to store those passwords
for you. Then you can simply retrieve
every time you want to login in a
continue with this. But there's a danger
with that.
>> Once this password manager is
compromised, all your accounts will be
compromised.
>> Yeah.
>> So the moment you you decide that I want
to use a password manager like the
Google password manager,
>> then be ready to protect that account
like a new house.
>> Yeah.
>> Yeah. So meaning that whenever you log
if you're in the public service vehicle
hide it cover it do it under the blanket
>> not really
>> to protect it like a new house I meant
this ensure that that Google account the
password to me is very unique
ensure that you have enabled two factor
authentication
now for this case don't use the normal
SMS uh authentication
>> use the the no the authenticator app.
>> Oh, the authenticator app. What if it
also gets hacked? Cuz now hackers are
passing through everywhere.
>> Now that one is only possible if I have
access to your phone
>> physically. Now the device
>> not not just physically,
>> not just physically but even through
connections or networking.
>> Now for that case now to ensure that
this one is safe.
>> Mhm. be aware of different forms of
social engineering. That's like the
fishing
that link will give that person access
to your device
Facebooks
by opening that picture I'm able to take
over your phone with just a selfie.
>> Yeah.
>> Right. So you'd advise strong passwords
uh to a fair that is two factor
authentification.
>> Yeah.
How many digits? 12 plus
>> at least 12. Yeah,
>> 12 is too much.
>> To remember,
>> of course, you can
memorize a 12.
>> If you if you can't remember
>> a 12digit password,
>> you can use the the password managers
for that case.
>> Yeah. What about somebody who's using an
Instagram password to login into
Facebook even though all of them are
meta products, but they're using it even
to log into Tik Tok, LinkedIn. Is that a
danger? Is it dangerous?
>> Of course, it is. If I get that
password,
>> maybe there is a data breach in one of
the portals or the systems that you're
using.
>> Okay,
>> there's a data breach as a hacker. I
have your password for that particular
account cuz I'll try accessing different
accounts using that password.
You see the attack surface.
>> Yeah.
>> So the damage will be spread all over.
>> Right. And maybe let's deep dive as well
like are there patterns that a hacker is
likely to carry in terms of their
character that you can trail that you
can let's say you can keep up and make
record and know
I think you had explained it earlier on
but maybe what is the character of a
hacker in terms of uh you
like when they hacked into it I don't
know what they did but nothing happened.
Yeah,
>> even the president's site etc. What is
what are the characteristics of this
person who is this devil who is
demanding 41 million Kenya shillings as
a ransom?
>> Can you tell that the tellt tell signs
there's a person here?
>> Yes, of course. The first thing that any
hacker will do when he logs in to any
system is to try to maintain access.
>> Maintaining access it means that I'll
have to keep you out of this.
Yes.
So, I kick you out of this house. Then
I'll try to change the recovery methods.
You're using your phone, your email
address as a recovery, and I still don't
have access to your mobile phone. I
don't have access to your email address.
So, I have to change for me now to stay
here. Otherwise, if I maintain those
recovery accounts,
>> what will happen?
So those are the things
out of the system the recovery
details will be changed and even some of
your data in
>> yeah
all sort of things will happen even the
name might change. Yeah. And I want us
to deep dive now into your uh your
profile and how you guys are helping
this in terms of digital forensics
policies and law. For example, how uh
does the data protection act of 2019
come to play for companies in breach of
of of data and privacy? And also maybe
for a company uh in terms of them
securing their data in a way that it's
only accessible to mandated persons that
are professionally allowed to handle
this data ethically. How does it run
that part?
>> Now um data protection act of 2019
brought what we call the office of data
protection commissioner the ODPC. ODPC
oversees how businesses handle customer
data. Right
>> now in businesses we have two two two
people here two parties in fact three
three parties.
>> We have the data controller we have the
data processor and we have the data
subject.
>> Data subject Brian is me and you. We are
the data owners. So we become the data
subject. The data processor is the data
controller is the one who determines
which kind of data should be collected
from the data subject. Then we have the
data processor who now processes this
data on behalf of this data controller
or of this business. A perfect example
>> is that a third party?
>> Yes. In most cases it is a perfect
example.
>> Mhm.
>> I have a company, I have staff, I have
their data, their payroll data, but I
rely on another company to prepare the
payroll and even pay them.
>> Is that even secure and safe? Now let's
go back to the data protection what he
talks about such
>> right please go ahead
>> because you are now engaging another
third party
>> to process some data
>> on your behalf
>> you need to have what what we call the
data processing agreement
>> between the two of you
>> such that if something happens the ODPC
would not come for this third party
>> it will come for you as the data
controller because you are the primary
the primary legal person who is
collecting who is determining which kind
of data to be collected from your
customers. So not come for this person
but it will come it will come for to you
who collected this information
so that my business can continue
>> I'm thinking of uh uh is it the the
health records at at let's say NHF and
SH and NSF way back I'm also looking at
IDs yeah and the ecizitizen platforms so
maybe how's the back end of that and how
is it working If you are to explain,
>> of course
the government API, if you're asking
about
>> how they connect like ID number and
extract some information from system to
lo into your citizen, you need your ID
number.
>> Yes, true. Where where are they getting
this information? So there is what we
call the government API. You going to
all this sort of information from the
birth certificate on a register 18
years. you are given ID number. This ID
number is connected to K. This K pin is
this this this this. So at the end of
the day
>> if you have now like um a system most in
most cases in government systems that
needs this information maybe to verify
or do this and this they usually we
usually have what you call the
government API. So once you
>> what does it mean by the way in full?
Somebody's like what is API? API is
application programming interface that
helps this server to fetch some
information or data from another server.
>> Right.
>> Yeah.
>> So you in a letter information from this
server you verify then you query all
those sort of things.
>> Yeah. But somebody will also ask why are
government websites just prone to
hacking? Yes. They have the data that's
well needed. There was a time there was
a debate on I think it was a healthcare
partnership program between the US and
Kenya and Marco Robbo sounded off on it.
He said you know we've had this you know
in fact it's a it's a five year or a 10
year plan but again at some point they
mentioned they needed Kenya's healthcare
data records you know and somebody said
oh we are just sold d is a whole banter
on data and privacy but still back to
the question why are government sites
prone to hackers?
Now you need to understand one thing
Brian I'm also from the government
sector
>> um and I've seen this as as a challenge
you see today we can identify that there
is a serious gap a security gap that we
need to fixing this gap we need some
money and money maybe you're going to
procure a solution this procuring a
solution is now where the problem is we
now go back to procurement
that we need to have a budget this
budget need to do this and this is step
step
procurement. So with all this time being
wasted in procurement and we still have
this gap in
so there are hacker somewhere who has
been monitoring us will do what will
take advantage of this gap and exploit
the system.
>> Yeah. So that's where the problem is.
>> Decisions making in government sectors
is not that as quick as decision making
in private sectors.
>> Yeah.
>> Come private or system. What do we need?
We need to procure a new firewall. Do we
have money for that?
>> Yeah.
>> Because decisions there is quicker
faster quick compared to government.
>> It's a process and
>> and of course these government systems
again they are interconnected. So if one
interfered with chances that these other
systems interfered with
>> quite high
>> there was even a debate I think was it
in Senate where they were questioning
why was uh the data of this uh
government service being held by a third
party I don't know what entity was it
it's very common among genz
conversations where they're saying bon
third party it's it's escaping my mind
anyways here and there was huge debate
on that too as well but let's also look
at the cyber crimes act of 20 uh is it
2018 there's a 2018 one
>> and and then now the I think it's the
computer misuse
and cyber crimes act of 2018 maybe how
does it impact now
>> uh navigating online and how you guys do
investigation forensic investigations
and analysis
>> there's a problem some some 15 years ago
>> all right
>> where I could hack your system I take
money from your system or just interfere
with how your system works
But you don't take me anywhere.
But now with this cyber crime act in a
letter issues
cyber crime in a tries to do what? To
interfere with the system.
>> Yeah.
>> In fact in a define what cyber crime is
all about.
evidence connecting this person to this
particular attack
>> then this is the repercussion and these
are the consequences
in terms of legal discharge
some
basis so they had to formulate a policy
>> yes they had to come up with a policy
the same way with the data protection
to mishandle customer data.
>> Someone is just calling you 100 times
just sending you some endless messages.
What are you supposed to do?
>> Right?
>> There was no act for that.
>> So in terms of legal that one was a plus
because today I try to hack a system I
interfere with the system functionality
there's evidence connecting me to that
particular action.
>> Right.
>> Yeah.
>> Maybe in the same breath there's an
interesting question here. Maybe for
example when you secure evidence for law
enforcement what makes digital evidence
legally admissible in court cuz that's
when now person has escalated it and
also maybe you can take it even to when
people are trending hashtags malicious
hashtags
uh sometimes smear campaigns etc or even
bullying cyber bullying too it's part of
that as well so how do you uh secure and
make digital evidence legally admissible
in court have you ever found yourself in
incidences where you know a client or a
person is escalating it to the courts of
law.
>> H I was once in such nilend could
present as an expert. Okay.
>> I was hired as an expert to do some to
collect some evidence from CCTV and I
went to to present
>> brand. Um what if I tell you now that
you might have screenshot the WhatsApp
you present them to the court of law
like evidence. Yeah.
>> What if I tell you that?
>> Mhm.
>> Unless it is a serious criminal case. A
serious criminal case.
>> Yeah. WhatsApp communication.
>> Yeah.
Why?
Because the clear boundary between
privacy
>> Mhm.
>> evidence
at the same time
but these are these are
private what conversation we are having
with you.
>> Yes.
>> It will not be treated as an evidence.
>> So maybe what makes it now admissible?
>> Number one, when there is a court order,
>> right?
Now bring those evidence and as you
bring those screenshots do not delete
the original conversation
evidence.
So you you you need to have what
>> the original evidence. Now if it is now
for the server for the business spaces
do not give us evidence
the opensource softwares
>> without any license. No this evidence
the tools that you have used to extract
this evidence commercial tools you
paying for a license otherwise these
premium tools that you use the open
source
>> may not be accepted.
>> Right. Well, let's pause on it as we uh
take feedback. And we are asking you on
our question, what online scum have you
ever fallen for? Yes. What online scum
have you ever fallen for? And we also
ask you to tell us your wildest hacking
stories. And there's interesting
feedback coming through. Uh there's
Julius Rea tuned in from Ner Town. Shout
out to you. And then there's minor
Steven buying Facebook products. Is it a
thing Chris with buying Facebook
products?
>> Yeah, Kenya, we are still not yet there.
Uh-huh.
>> In terms of online marketing,
>> right,
>> we are not yet there.
>> There's trust issues. There's stress all
over. There's financial pressure all
over. So, Kenyans, other funny Kenyans
will take advantage of this online stuff
then get some money.
>> Okay. Uh, next um we also have Sifuna
Brian. Oh, interesting.
you know, dating Amazu from Germany,
paying delivery fee for gifts where
this happens a lot as well where you
somebody text you and they tell you, you
know what, I just spotted your profile
from the US and here we are. Yeah.
>> At that point, Brian,
>> the scammers are exploiting emotional,
>> right?
>> The loneliness in you. Maybe you're
lonely. You want someone then boom. So
they've noticed maybe you're on a dating
>> because they have they have so they'll
exploit that in you because you're a
human being. So that emotional aspect
you want to talk to someone, you want to
chat with someone, you want to call
someone, they come
girlfriends or boyfriends.
>> Yes. And then second last but not least
2013. Okay. Interesting. And then Palmer
buying products through Facebook. nil
Joshua and I think you've reacted to
that too as well and I want us to close
this conversation to and I understand
you have a book but you'll tell us uh uh
the story behind the book as well as you
close it up I want you to maybe explain
to us what what is the major challenge
is there like a skill gump uh issue in
the cyber security space because I I
interviewed I think it's on a different
show anyways he was telling me cyber
security experts are not many in Kenya
so they're calling on more to come on
board in terms of training skilling and
even upskilling Would you say that's the
main challenge as we get into the book
too as well?
>> Yes, Brian I'll say that's the main
challenge. We have so many cyber
security
students can say so even those who call
themselves professionals but how many
can come near KBC coini idea
>> there are few so that's a that's a a
major challenge we are having we don't
have experienced cyber security
professionals in Kenya
>> and where is this a problem coming from
because we don't have again serious
institutions that are teaching serious
cyber security. Most of these you
sto
institutions that are teaching cyber
security. That's why I told you as we
began the show that cyber psychology
>> and human hacking. It's a new concept.
>> It's a new concept foreign institutions
are there teaching that
>> right. Absolutely. So we need more on
board. Talk about your book shortly as
we exit and how they can get to purchase
it. A short story line behind it.
Understand you have a series of them too
as well. Thank you brand. These are the
the book is the error.
>> The teacher I never wanted.
>> The error the teacher I never wanted.
Interesting.
>> The book basically talks about the pain
the mistakes that we do in life and the
unexpected lessons that we get from
those pain.
>> It start with telling us the beginning
of errors where the errors began. The
things we used to see our fathers doing,
our mothers doing, our elder brothers
and sisters doing, our uncles doing and
we learn from them. Because when a child
is born this child is empty
by doing so
and at the right time the appointed time
the child will do the same things that
the father
>> replicate. Yes.
>> So it's generational patterns. So at the
end of the day we make errors. We think
we are doing the right thing but we make
errors. But these errors they give us
lessons. They give us another another
wisdom,
>> okay,
>> on how we navigate.
>> So if so, if a person is going to buy
I'm being told you're on a timeout
button. We're just about to exit. So if
how can they buy the book? Where is it
and how will it be of help in 10
seconds? Look at them in the camera.
>> The book is is on Nura Jun Kilimon. To
read it, you can visit my website
www.hayer.com.
>> Yeah. Does it have a number too?
>> Yes. Okay.
>> 0799
874578.
>> Absolutely. I think they they'll piece
up all that information and get to buy
this book. I hope that's my copy to it.
We'll talk the air.
>> Thank you so much. All right.
>> All right. Thank you so much Christopher
Hayier for being here. He's a
coordinator at Kenya Cyber Security and
Forensics Association for your
incredible and valuable uh insights in
this conversation. We also want to thank
you for watching us from 7 to right
about now. If you missed anything, I
promise you'll find it on YouTube at
Y244 channel. And we continue the
conversation as we go off on the hashtag
which is power talk power talk show, not
power talk TV show. A man at Brans 101.
Thank you for watching. See you next
time right here on Power Talk.