Submind YouTube summaries
Thumbnail for The intersectionality of Human Psychology, Security and The Era of AI and Misinformation.

The intersectionality of Human Psychology, Security and The Era of AI and Misinformation.

Watch on YouTube

Video summary

The video addresses the critical intersection of human psychology, cybersecurity, and the escalating challenges posed by artificial intelligence and misinformation. Speaker Autumn Nash highlights that cybercrime now represents an economy larger than most nations, costing $6 trillion globally in 2021 alone, with the financial burden ultimately passed down to consumers through higher prices and insurance costs. She argues that technology is advancing faster than society's ability to adapt, leaving many without the necessary media literacy to distinguish truth from falsehood. This gap creates a vulnerable environment where stress and uncertainty impair human decision-making, making individuals more susceptible to manipulation when they are tired, rushed, or emotionally compromised. A significant portion of the discussion focuses on how security breaches often stem not from technical failures alone, but from social engineering that exploits human psychology. Nash points out that 60% of data breaches involve humans, frequently through credential misuse or errors made under pressure. The rise of AI has lowered the barrier for creating convincing disinformation; malicious actors can now use deepfakes and automated tools to impersonate loved ones or officials in real-time video calls, causing immense emotional distress and financial loss. Furthermore, the open-source ecosystem, which comprises 70% of tech infrastructure, faces new risks as AI agents are used to bully maintainers or hide malicious code within legitimate packages, demonstrating that technical solutions must be paired with a deep understanding of human behavior and social dynamics. To combat these threats, Nash advocates for a holistic approach that combines technical validation with robust community education and media literacy. She emphasizes the need for humans to remain in the loop to validate AI outputs, ensuring that agents operate under strict least-privilege principles similar to human employees. The speaker stresses the importance of fostering a culture where individuals feel comfortable questioning sources, fact-checking information before sharing it, and having open conversations about technology with family members ranging from grandparents to children. By building resilience through regular backups, diverse community collaboration, and teaching critical thinking skills, society can better navigate an era where the line between reality and fabrication is increasingly blurred by advanced AI capabilities.
Read the full video transcript
Um, so, I'm Autumn Nash. I'm a software engineer at Microsoft. Um, today I'm going to be talking to you about the intersectionality of human psychology, security, in the era of misinformation. So, if we measured cybercrime right now, and the money that is lost with cybercrime, um, it would be a bigger GDP than most countries. $6 trillion in 2021, and it's only gotten it's only gotten worse over time. It would be the third largest biggest economy after the US and China, which is wild. And when you think about that, not only is it businesses losing money, but it's people and everyday people losing money. And when businesses lose that much money, that cost is passed down to the consumer, right? Or insurance companies, which still gets passed down to the consumer. We're living in a world where you can't believe what you see, hear, and technology is moving faster than society can keep up. We don't have the education or media literacy as a whole to keep up with the way that technology is moving. Has anybody have to had to tell your grandma on Facebook that a plant's not real, or a picture's not real, or remind somebody, "Hey, that video looks a little off. Have you looked at the lettering?" How are we supposed to protect each other and one another in a world where we don't know if we're what we're seeing and hearing is true? And I bet you can imagine with me the implications this will have on geopolitical climates. We're in a time with so much uncertainty that it only exacerbates the way that humans deal with stress. When humans are stressed and you're making decisions more quickly and kind of under uh stress, you don't always make the best decisions, right? Has anybody ever tried to make a decision when like you're like dinner's burning? You know, you're in the middle like your kids asking you for something. We're not our best selves when we're stressed, right? A lot of times I think we try to fix security, especially like cybersecurity, with technical um solutions, which there is a technical part to it, right? But humans Okay. Security in general, some of the most impressive post-mortems and security breaches are never because they did something really just technical. They're always they walked through the front door in the most amazing way possible. If you look at the biggest biggest breach Target ever had, it was a disgruntled contractor. Um if you look at some of the recent uh open source, we've had AI agents bully maintainers, you know, like it's getting to the point where well, not even getting to the point. I feel like it's always been where we make one small mistake and it costs us a lot because we're not we're not thinking about how security and social and emotional um the aspect of that really all comes together. Human psychology has a lot to do with how we show up every day. Your bad day that you didn't sleep a lot, maybe you didn't get enough rest, you're going to be very different in the way that you handle a problem in a stressful situation. And I think we really have to look at have a holistic point of view when it comes to um cybersecurity, special especially in a time where a lot of things are uncertain. And we have AI making AI and misinformation and the spread of that really making fooling each other cheap, basically. It no longer takes a big production to make something into fool somebody's eyes. You can do it for 5 seconds on a cell phone app. So, the World Economic Forum says that misinformation and different disinformation is one of the biggest short-term global risks that we're facing today. They're worried that it's going to not only erode trust, but destabilize force. It'd be a destabilizing force. When we're talking about solutions to a problem, I think the first part that's the first part of the solution I like to talk about is business because I think it's that a lot of times when it's better for people in general, we ignore it until we really point out the bottom line to people. And I think really thinking about the numbers and the bottom line helps motivate people to do the right thing. 60% of data breaches involve humans. It's usually social engineering, credential misuse, or error. And a lot of the times it's based off of putting that human in a situation of stress or making them make quick decisions. Ransomware is present in 44% of breaches. And I think the last average it took what 21 days by on average for companies to get um their ransom like ransom issues like worked out. So, can you imagine being down for 21 days on average? Like what company can survive that? And the global cost of data breaches is 4. 8 8 million dollars. Raise your hand if you've got a email or a letter saying that your data has been in a data breach. >> [laughter] >> You know? And think about it, we're giving these apps, we're giving just everything more and more information. We're like, "Hey, this new assistant is going to go through my emails. It's going to write me text messages. It's going to do all these things." Well, it's also crawling your text message. It's crawling your email. It knows everything about you. You know? And that And some of that is to do you a service and it is a positive thing until the wrong person gets that information. Right? So, if we're going to ask people for that type of data and information, it's kind of our responsibility as a society to educate them how to be able to to make good decisions on who they give the data. And then the people that you give your data to are responsible of keeping your data safe. So, for instance, as we all talked about kind of letting our grandmas know like, "Hey, like maybe you shouldn't wear your meta glasses in private situations." >> [laughter] >> Or, hey, that's probably not a real animal. But, I mean, honestly, and then you think about it like, our children are growing up and what is the source of truth for our kids, right? My kids like use Alexa. They know how to Google more than they like when I was little, I used the Dewey Decimal System and I went to a library. That's Their kids have a completely different upbringing. Our grandparents are still learning how to copy and paste and Google sometimes, you know? And if you can fool a Hong Kong bank to give you $25 million with both video and sound on a video call, do any of us know, like truly, who we're talking to? Like, how do you verify that you're on the phone with your actual kid? If somebody calls you tomorrow, think of somebody that you really care about, like your child, I don't know, your spouse, grandparents, somebody that you feel like a deep responsibility for. And if they call you tomorrow and somebody says, "Hey, we have this person, your daughter or whoever, and you need to give me $50 $50,000 right now, or you'll never see them again." In this current climate, a lot of people have a fear that someone may leave their house and not come back. You can't just call them back, right? So, and the fact that you could have, you know, that person's loved one's voice come over that phone and say, "Yes, you really have me." That's a very scary thought that people are going to actually have to deal with. Also, open source is 70% of all of our infrastructure in tech. And the fact that we're currently dealing with how to figure out how we can still take in like contributions from people with AI. But, how do we know they're secure? And how do we know that we can use AI in a way that is going to continue to not be a supply chain risk? I think for the most part humans try really hard to make good decisions. We try to follow, you know, best practices and the rules. Sometimes it takes one link, one credential. When you're moving faster, you're trying to get things done. We're all doing much more with less. Right now we are half most of our teams are down. We're trying to do what we can with the workloads that we're given. And the added stress of just daily life, what's going on in the world, trying to do the work of three people, that puts you in a situation that's setting you up to make decisions quickly. I want to do a poll. So, out of everyone here, raise your hand if you feel like it applies to you. So, who reads the newspaper? Okay. Who gets your news from like an evening news, like, you know, like an actual news show on TV? Okay. Now, who gets your news from like a social media source, like TikTok, Facebook, Instagram? And it doesn't have to be like legitimate news, it just needs to be like, "Hey, this thing popped up." And then you told your friend about it, like, this, you know, something that was alarming. So, most Americans are actually getting their media their news from the media. They're They're interacting with media and social media and like different forms of finding their information out, mostly from social media. Right now, if the recent mergers go through, two people that are related to each other will own majority of the ways that we consume media. If we had a technology or a form of how we do business and two companies out of the entire world had complete exclusive asset access to it, would that be a supply chain risk? We literally have a supply chain risk to our information at this point. I don't know about you, but being a kid was hard before Facebook, before Instagram. Do you remember like burn books and like rate like boys rating girls back in the day? Now, let's add the fact that somebody can take your face and make really disturbing AI pictures of you with no clothes on, and then they can share it and send it to everybody in your class. On top of that, we have it where we know that when a young boy opens up TikTok, if you today opened up TikTok and started an account and made it for, you know, a 13-year-old boy, it's going to start feeding you a like a certain algorithmic path of videos that isn't isn't always the kindest to women. Women are seeing an increased amount of cyber harassment and bullying. Gronk has been in trouble with the year with European government for the amount of sexually explicit child imagery that it's come up with. And this is what like our kids can get access to. Not only do we have to protect them from So, just think about it. You could block your kid from explicit websites, but now they can make the explicit comment content with AI. We don't even have like parental blockers to like look for that. You know what I mean? You can't block something that hasn't been made yet. So, just like we're still working we're still working on adults getting the media literacy and the guardrails to kind of deal with the new technologies, our kids are still learning how to navigate the world just in general. And now we don't even know we don't have the tools or like the literacy for you know, your normal human your normal adult to keep their kids safe cuz we are still trying to figure out how to teach them the media literacy for them to navigate this world. Four in 10 young adults get their information from TikTok. You don't exactly have to be an expert to make a TikTok video. You don't have to be a like you there's no validation on that this person is right of the subject that they're talking about and this is where our kids are learning. Back in the day like we used to go outside and come home when the like, you know, when the when it got dark outside and the lights came on. But now our children aren't even safe in our own homes. If your kid is somewhere with an unfiltered iPhone or YouTube, they can be influenced just in your house. That's a very scary thought. Not only do we have to worry about our children, but people over 60 are disproportionately being hit with internet crime. And it's coming in forms of communication that you wouldn't expect. A lot of people may need, you know, tech support. Um invest They're trying to make good investment choices. Business emails. Raise your hand if you get scammed I mean scam phone calls. And everyone in this room, think about it. We are probably more technically uh knowledgeable than maybe your average person, right? So, not everybody has the same tools as everybody in this room or at these kind of a conference, and they may not know that the IRS doesn't call you and ask you for your information. There are a ton of links that are They look like an Amazon link, and just a few things are different or a few letters are different, which are completely which you they're now giving their information out. >> [snorts] >> They're also more likely to be Well, I'll start. If you think about it, these scams we have been going on, and they've been something that we've had to worry about. But now, if you can make something look exactly like it, you can get on a video chat and make something like make it look exactly like somebody's talking or someone that they know or even if it's like a government official, if you don't have the knowledge and the context to know that you have to now like um question those things, they're at even a greater risk with greater risk, and even with the tools that we may have used previously to kind of mitigate those risks. It's going to get harder to really spell out that um who to trust and who not to trust. Like we're going to get back to the day where you have to have like a family password, you know what I mean? To truly verify that the other person on the other side of the phone is who you think it is. I was going to add disinformation to the end of my talk title, but if you saw it, it's kind of a mouthful to begin with, so. I think that there's misinformation where you're not intentionally mistaking. Like you're not inten- intentionally spreading misinformation. Or, you know, bad information, which older people over the age of 60 are more likely to do, but it's everywhere. We're all seeing things on the internet that are absolutely not true. But then you have disinformation that people are deliberately fabricating. And then you have the aspect of when like you're doing malinformation where you're deliberately public- um, public- uh, publicizing private information or personal information. And I think this is going to like these this is important to know, and I don't think we're really like educating people and giving people the context to know like there's people who are trying to not intentionally misin- and misinform you. Sometimes it's our friend sharing something on Facebook because they thought it they saw something, they were outraged, and they just wanted you to know about it. And then there's people that are intentionally trying to find information to like create that harm. So, how do we fix it? In business, we want to be able to back up our data regularly. We really need to know what we're building, so it's going to take a lot of validation from humans. So, I think we're as much as that we can as much as we can be efficient and move faster with um with AI, it's still really important to have humans validating, but we need to find different ways to actually do the validating. Like whether it be artifacts or different screenshots and using metadata, we're going to have to really get to the point where we're proving what we're building and what we're downloading. I don't know if you saw the breach with uh Open Claw and how it downloaded itself on 4,000 different hosts. And the fact that we're using more and more AI to commit to different repos, especially open source, which is packages that not only do companies use, but are just used in a ton of I mean, it's 70% of infrastructure. It's a lot of our operating systems. And then if you had malicious code that was hidden in there, like we saw with I forget what it was. I forget which one it uh what the what the file was, but we saw the guy that did the Trojan Horse. And that was not only with social engineering of kind of bullying the maintainer and telling him, "Hey, you need another maintainer." and kind of making him depressed, but also on top of it, they built a very technically amazing uh Trojan Horse that then had those binaries hidden in the files. So, that's just an like example of the social engineering and technical engineering. So, we really need to be able to validate what we're doing. And think about it. If you think about it in the context, you can go and get a whole bot farm that influences people to take the next upgrade. So, you can actually cause the fear to get them to download those malware even faster. So, I think it's important to know what you're getting. It's important to have trusted sources and a trusted kind of community. Um I think using security best practices, but also using them when it comes to AI. You don't just let your agent just go and do whatever it needs to do. It should have the same like least privileges that you would give a human. Um conducting regular security audits and really auditing what your agents and your humans are doing. Uh the agent There was an agent um not too long ago where the developer had explicitly said, "Please don't touch these packages. Use everything else." And then they had this really great like um back and forth and he was and the agent was like almost kind of talking as it was like the senior engineer explaining how they found this great workaround, but that workaround's a security risk, right? So, it's amazing that they were able to do that, but not in the positive way that you really think about it. Um I think cybersecurity education and building a culture is going to be really important. We have to have like a habit of thinking about security because again, when you're making hard decisions, when you're making those decisions quickly, kind of having that habit of how you're going to go through things is really important. I think having recovery point and backups and being resilient architecture can really help too. I don't know if you all saw uh there was a blog post yesterday where someone had been using an agent to be to move over their um infrastructure for their blog and some of the like teaching that they were doing and they were moving it over on AWS and using Terraform and the agent was looking for uh I guess the stack or like where what it had already had created and it started recreating something else and he was very confused. So, he was like, "Delete those resources." The agent not only deleted a production database, it deleted um all of the backup and recovery and deleted two and a half years of classes. And if you think about it, if you don't know one Terraform command, but this AI built majority of this infrastructure for you, right? So, maybe that's a command that you weren't notice like you weren't used to seeing. So, it's like how do we get the context to go with this new level of extraction? It's like the fact that some people didn't know the cloud were a bunch of Linux servers, you know? Because it's that level of abstraction, so if we need the security like best practices, but we also have to have the context to know how do we help AI to make those decisions and how we continue to have humans making that validation. So, this again is going to be a holistic process. We need to kind of come at it from like a community aspect, right? So, don't be part of the problem. Fact check things before we posting it, but also like have those conversations with people, right? Like help people to get the wonderful knowledge that everyone in this room probably has because maybe we do know a little bit more about technology and we can help people navigate the things that aren't true and have those conversations. Help grandma, help your kids. Like I have a constant conversation with my kids like, "Hey, do you want Alexa in your room? Alexa can be listening to you outside of, you know, you talking to it." Like having a like conversations so people can understand what they're buying into. Um, having the conversations of uh, like when you see something on YouTube, like why do you think that person is influencing you to buy that? Do they think they really care about you drinking Prime and it has less sugar than Gatorade or is it because they're trying to sell something to you? Like we don't want people to lose their curiosity because sometimes that's what saves you, right? So, being curious, asking questions, not being part of the problem, and really like fostering media literacy within our community. I know like a lot of my talks end up in community somehow, but it's because I truly believe that like when you look at open source, I love open source, and you see that like when somebody has a cyber security or a security issue, CVE issue if you look at the way that they like solved Log4j, when you have four of the biggest companies and the smartest people working on it, you are going to have a better outcome than if you do it siloed in a room with three other people, right? So I think that it's got to be a holistic um form of educating each other and kind of like being good stewards and educating other people and ourselves. They're also coming out with a bunch of tools that we can use like Bot Slayer, bots, and signal um certified content coalition metadata model uh Which button? I have no idea. Well, that was my last slide anyways, but thank you all for listening.