The intersectionality of Human Psychology, Security and The Era of AI and Misinformation.
Watch on YouTubeVideo summary
The video addresses the critical intersection of human psychology, cybersecurity, and the escalating challenges posed by artificial intelligence and misinformation. Speaker Autumn Nash highlights that cybercrime now represents an economy larger than most nations, costing $6 trillion globally in 2021 alone, with the financial burden ultimately passed down to consumers through higher prices and insurance costs. She argues that technology is advancing faster than society's ability to adapt, leaving many without the necessary media literacy to distinguish truth from falsehood. This gap creates a vulnerable environment where stress and uncertainty impair human decision-making, making individuals more susceptible to manipulation when they are tired, rushed, or emotionally compromised.
A significant portion of the discussion focuses on how security breaches often stem not from technical failures alone, but from social engineering that exploits human psychology. Nash points out that 60% of data breaches involve humans, frequently through credential misuse or errors made under pressure. The rise of AI has lowered the barrier for creating convincing disinformation; malicious actors can now use deepfakes and automated tools to impersonate loved ones or officials in real-time video calls, causing immense emotional distress and financial loss. Furthermore, the open-source ecosystem, which comprises 70% of tech infrastructure, faces new risks as AI agents are used to bully maintainers or hide malicious code within legitimate packages, demonstrating that technical solutions must be paired with a deep understanding of human behavior and social dynamics.
To combat these threats, Nash advocates for a holistic approach that combines technical validation with robust community education and media literacy. She emphasizes the need for humans to remain in the loop to validate AI outputs, ensuring that agents operate under strict least-privilege principles similar to human employees. The speaker stresses the importance of fostering a culture where individuals feel comfortable questioning sources, fact-checking information before sharing it, and having open conversations about technology with family members ranging from grandparents to children. By building resilience through regular backups, diverse community collaboration, and teaching critical thinking skills, society can better navigate an era where the line between reality and fabrication is increasingly blurred by advanced AI capabilities.
Read the full video transcript
Um, so, I'm Autumn Nash. I'm a software
engineer at Microsoft.
Um, today I'm going to be talking to you
about the intersectionality of human
psychology, security,
in the era of misinformation.
So, if we measured cybercrime right now,
and the money that is lost
with cybercrime, um, it would be a
bigger GDP
than most countries.
$6 trillion
in 2021, and it's only
gotten it's only gotten worse over time.
It would be the third largest biggest
economy after the US and China, which is
wild.
And when you think about that, not only
is it businesses losing money, but it's
people and everyday people losing money.
And when businesses lose that much
money, that cost is passed down to the
consumer, right?
Or insurance companies, which still gets
passed down to the consumer.
We're living in a world where you can't
believe what you see, hear,
and
technology is moving faster than society
can keep up.
We don't have the education or
media literacy as a whole
to keep up with the way that technology
is moving.
Has anybody have to had to tell your
grandma on Facebook that a plant's not
real, or a picture's not real, or remind
somebody, "Hey, that video looks a
little off. Have you looked at the
lettering?"
How are we supposed to protect each
other and one another in a world where
we don't know if we're what we're seeing
and hearing is true?
And I bet you can imagine with me the
implications this will have on
geopolitical
climates.
We're in a time with so much uncertainty
that it only exacerbates the way that
humans deal with stress.
When humans are stressed and you're
making decisions
more quickly and kind of under uh
stress,
you don't always make the best
decisions, right? Has anybody ever tried
to make a decision when like you're like
dinner's burning?
You know, you're in the middle like your
kids asking you for something. We're not
our best selves when we're stressed,
right?
A lot of times I think we try to fix
security, especially like cybersecurity,
with technical um
solutions, which there is a technical
part to it, right?
But
humans
Okay.
Security in general,
some of the most impressive post-mortems
and security breaches are never because
they did something really
just technical. They're always they
walked through the front door in the
most amazing way possible. If you look
at the biggest biggest breach Target
ever had, it was a disgruntled
contractor.
Um if you look at some of the recent
uh
open source,
we've had AI agents bully maintainers,
you know, like
it's getting to the point where
well, not even getting to the point. I
feel like it's always been where
we make one small mistake and it costs
us
a lot because we're not we're not
thinking about how
security and social and emotional
um the aspect of that really all comes
together. Human psychology
has a lot to do with how we show up
every day. Your bad day that you didn't
sleep a lot,
maybe you didn't get enough rest, you're
going to be
very different in the way that you
handle a problem in a stressful
situation.
And I think we really have to look at
have a holistic point of view
when it comes to um cybersecurity,
special especially in a time where a lot
of things are uncertain.
And we have AI making
AI and misinformation and the spread of
that really making
fooling each other cheap, basically. It
no longer takes a big production to make
something into fool somebody's eyes. You
can do it for 5 seconds on a cell phone
app.
So, the World Economic Forum says that
misinformation and different
disinformation is one of the biggest
short-term global risks that we're
facing today.
They're worried that it's going to not
only erode trust,
but destabilize force.
It'd be a destabilizing force.
When we're talking about solutions to a
problem, I think the first part
that's the first part of
the solution I like to talk about is
business because I think it's that a lot
of times when it's better for
people in general, we ignore it until we
really point out the bottom line to
people.
And I think really thinking about the
numbers and the bottom line helps
motivate people to do the right thing.
60% of data breaches involve humans.
It's usually social engineering,
credential misuse, or error.
And a lot of the times it's based off of
putting that human in a situation of
stress or making them make quick
decisions.
Ransomware is present in 44% of
breaches.
And I think the last average it took
what 21 days by on average for companies
to get
um their ransom like
ransom issues like worked out. So, can
you imagine being down
for 21 days on average? Like what
company can survive that?
And the global cost of data breaches is
4.
8
8 million dollars.
Raise your hand if you've got a email or
a letter saying that your data has been
in a data breach.
>> [laughter]
>> You know?
And think about it, we're giving these
apps, we're giving
just everything more and more
information.
We're like, "Hey, this new assistant is
going to go through my emails. It's
going to write me text messages. It's
going to do all these things." Well,
it's also crawling your text message.
It's crawling your email. It knows
everything about you. You know?
And that And some of that is to do you a
service and it is a positive thing until
the wrong person gets that information.
Right? So, if we're going to ask people
for that type of data and information,
it's kind of
our responsibility as a society to
educate them how to be able to to make
good decisions on who they give the
data. And then the people that you give
your data to are responsible of keeping
your data safe.
So, for instance,
as we all talked about kind of letting
our grandmas know like, "Hey, like
maybe you shouldn't wear your meta
glasses
in private situations."
>> [laughter]
>> Or, hey, that's probably not a real
animal.
But, I mean, honestly, and then you
think about it like, our children are
growing up and what is the source of
truth for our kids, right? My kids like
use Alexa.
They know how to Google more than they
like when I was little, I used the Dewey
Decimal System and I went to a library.
That's Their kids have a completely
different upbringing.
Our grandparents are still learning how
to copy and paste and Google sometimes,
you know?
And if you can fool a Hong Kong bank
to give you $25 million with both video
and sound on a video call,
do any of us know, like truly, who we're
talking to? Like, how do you verify that
you're on the phone with your actual
kid? If somebody calls you tomorrow,
think of somebody that you really care
about, like your child,
I don't know, your spouse, grandparents,
somebody that you feel like a deep
responsibility for. And if they call you
tomorrow
and somebody says, "Hey, we have this
person, your daughter or whoever,
and you need to give me $50 $50,000
right now, or you'll never see them
again."
In this current climate, a lot of people
have a fear that someone may leave their
house and not come back.
You can't just call them back, right?
So,
and the fact that you could have, you
know, that person's
loved one's voice
come over that phone and say, "Yes, you
really have me."
That's a very scary thought that people
are going to actually have to deal with.
Also, open source is 70% of all of our
infrastructure in tech.
And the fact that we're
currently dealing with how to figure out
how we can still take in
like contributions from people
with AI.
But, how do we know they're secure? And
how do we know that we can use AI in a
way
that
is going to continue to not be a supply
chain risk?
I think for the most part humans try
really hard to make good decisions.
We try to follow, you know, best
practices and the rules.
Sometimes it takes one link, one
credential. When you're moving faster,
you're trying to get things done. We're
all doing much more with less. Right now
we are half most of our teams are down.
We're trying to do what we can with the
workloads that we're given. And the
added stress of just daily life, what's
going on in the world, trying to do the
work of three people, that puts you in a
situation that's setting you up to make
decisions quickly.
I want to do a poll. So,
out of everyone here, raise your hand if
you feel like it applies to you.
So, who reads the newspaper?
Okay.
Who gets your news from like an evening
news, like, you know, like an actual
news show
on TV?
Okay.
Now, who gets your news from like a
social media source, like TikTok,
Facebook,
Instagram? And it doesn't have to be
like legitimate news, it just needs to
be like, "Hey, this thing popped up."
And then you told your friend about it,
like, this, you know, something that was
alarming.
So, most Americans are actually getting
their media their news
from the media. They're They're
interacting with media
and social media and
like different forms of finding their
information out, mostly from social
media.
Right now, if the recent mergers go
through,
two people that are related to each
other
will own majority of the ways that we
consume media.
If we had
a technology or a form of
how we do business and two companies out
of the entire world had complete
exclusive asset access to it, would that
be a supply chain risk?
We literally have a supply chain risk to
our information at this point.
I don't know about you, but being a kid
was hard before Facebook, before
Instagram.
Do you remember like burn books and like
rate like boys rating girls back in the
day?
Now, let's add the fact that somebody
can take your face
and make
really disturbing
AI pictures of you with no clothes on,
and then they can share it and send it
to everybody in your class.
On top of that, we have it where we know
that when a young boy opens up TikTok,
if you today opened up TikTok and
started an account and made it for, you
know, a 13-year-old boy, it's going to
start feeding you
a like a certain algorithmic path
of videos that isn't isn't always the
kindest to women. Women are seeing an
increased amount of
cyber harassment and bullying.
Gronk has been in trouble with the year
with European government for the amount
of sexually explicit child imagery that
it's come up with. And this is what like
our kids can get access to.
Not only do we have to protect them from
So, just think about it. You could block
your kid from explicit websites, but now
they can make the explicit comment
content with AI.
We don't even have like parental
blockers to like look for that. You know
what I mean? You can't block something
that hasn't been made yet.
So, just like we're still working we're
still working on adults getting the
media literacy and the guardrails to
kind of deal with the new technologies,
our kids are still learning how to
navigate the world just in general.
And now we don't even know
we don't have the tools or like the
literacy for you know, your normal human
your normal adult to keep their kids
safe cuz we are still trying to figure
out how to teach them the media literacy
for them to navigate this world.
Four in 10 young adults get their
information from TikTok.
You don't exactly have to be an expert
to make a TikTok video.
You don't have to be a like
you there's no validation on that this
person is right of the subject that
they're talking about and this is where
our kids are learning.
Back in the day like we used to go
outside and come home when the like, you
know, when the when it got dark outside
and the lights came on.
But now our children aren't even safe in
our own homes.
If your kid is somewhere with an
unfiltered iPhone or YouTube, they can
be influenced
just in your house.
That's a very scary thought.
Not only do we have to worry about our
children, but
people over 60 are disproportionately
being hit with internet
crime.
And it's coming in forms of
communication that you wouldn't expect.
A lot of people may need, you know, tech
support.
Um invest They're trying to make good
investment choices.
Business emails.
Raise your hand if you get scammed I
mean scam phone calls.
And everyone in this room, think about
it. We are probably more technically
uh knowledgeable than maybe your average
person, right?
So, not everybody has the same tools as
everybody in this room or at these kind
of a conference, and they may not know
that the IRS doesn't call you and ask
you for your information.
There are a ton of links that are They
look like an Amazon link, and just a few
things are different or a few letters
are different, which are completely
which you they're now giving their
information out.
>> [snorts]
>> They're also more likely to be
Well, I'll start.
If you think about it, these scams we
have been going on, and they've been
something that we've had to worry about.
But now, if you can make something look
exactly like it, you can get on a video
chat and make something like make it
look exactly like somebody's talking or
someone that they know
or even if it's like a government
official, if you don't have the
knowledge and the context to know that
you have to now like
um
question those things, they're at even a
greater risk with greater risk, and even
with the tools that we may have used
previously
to kind of mitigate those risks.
It's going to get harder to really spell
out that
um who to trust and who not to trust.
Like we're going to get back to the day
where you have to have like a family
password, you know what I mean? To truly
verify that the other person on the
other side of the phone is who you think
it is.
I was going to add disinformation to the
end of my talk title, but if you saw it,
it's kind of a mouthful to begin with,
so.
I think that there's misinformation
where you're not intentionally
mistaking.
Like you're not inten- intentionally
spreading misinformation.
Or, you know, bad information, which
older people over the age of 60 are more
likely to do, but it's everywhere. We're
all seeing things on the internet that
are absolutely
not true.
But then you have disinformation that
people are deliberately fabricating.
And then you have
the aspect of when like you're doing
malinformation where you're
deliberately public- um, public-
uh, publicizing
private information or personal
information.
And I think this is going to like
these this is important to know, and I
don't think we're really like
educating people and giving people the
context to know like
there's people who are trying to not
intentionally misin- and misinform you.
Sometimes it's our friend sharing
something on Facebook because they
thought it they saw something, they were
outraged, and they just wanted you to
know about it. And then there's people
that are intentionally
trying to find information to like
create that harm.
So, how do we fix it?
In business, we want to be able to back
up our data
regularly.
We really need to know what we're
building, so it's going to take a lot of
validation from humans.
So, I think we're as much as that we can
as much as we can be efficient and move
faster
with um
with AI, it's still really important to
have
humans validating, but we need to find
different ways to actually do the
validating. Like whether it be artifacts
or
different screenshots and using
metadata, we're going to have to really
get to the point where we're proving
what we're building and what we're
downloading.
I don't know if you saw the breach with
uh Open Claw and how it
downloaded itself on 4,000 different
hosts.
And the fact that we're using more and
more AI to commit to different repos,
especially open source, which is
packages that not only do companies use,
but are just used in a ton of I mean,
it's 70% of infrastructure. It's a lot
of our operating systems. And then if
you had malicious code that was hidden
in there, like we saw with
I forget what it was. I forget which one
it uh
what the what the file was, but we saw
the guy that did the Trojan Horse. And
that was not only
with social engineering of kind of
bullying the maintainer and telling him,
"Hey, you need another maintainer." and
kind of making him
depressed, but also on top of it, they
built a very technically
amazing uh Trojan Horse that then had
those binaries hidden in the files.
So, that's just an like example of the
social engineering and technical
engineering. So, we really need to be
able to validate what we're doing. And
think about it. If you think about it in
the context, you can go and get a whole
bot farm that influences people to take
the next upgrade.
So, you can actually cause the fear to
get them to download those malware even
faster.
So, I think it's important to know what
you're getting. It's important to have
trusted sources and
a trusted kind of community.
Um
I think using security best practices,
but also using them when it comes to AI.
You don't just let your agent just go
and do whatever it needs to do. It
should have the same like least
privileges that you would give a human.
Um conducting regular security audits
and really auditing what your
agents and your humans are doing.
Uh the agent There was an agent um not
too long ago where the developer had
explicitly said, "Please don't touch
these packages. Use everything else."
And then they had this really great like
um
back and forth and he was and the agent
was like almost kind of talking as it
was like the senior engineer explaining
how they found this great workaround,
but that workaround's a security risk,
right? So, it's amazing that they were
able to do that, but not in the positive
way that you really think about it. Um I
think cybersecurity education and
building a culture is going to be really
important. We have to have like a habit
of thinking about security because
again, when you're making hard
decisions, when you're making those
decisions quickly, kind of having that
habit of how you're going to go through
things is really important.
I think having recovery point and
backups and being resilient architecture
can really help too. I don't know if you
all saw
uh there was a blog post yesterday where
someone had been using an agent to be to
move over their um
infrastructure for their blog and some
of the like teaching that they were
doing and they were moving it over on
AWS and using Terraform and the agent
was looking for uh I guess the stack or
like where what it had already had
created and it started recreating
something else and he was very confused.
So, he was like, "Delete those
resources." The agent not only deleted a
production database,
it deleted um all of the backup and
recovery and deleted two and a half
years of classes.
And if you think about it, if you don't
know one
Terraform command, but this AI built
majority of this infrastructure for you,
right? So, maybe that's a command that
you weren't notice like you weren't used
to seeing. So, it's like how do we get
the context
to go with this new level of extraction?
It's like the fact that some people
didn't know the cloud were a bunch of
Linux servers, you know? Because it's
that level of abstraction, so if we need
the security like best practices, but we
also have to have the context to know
how do we help AI to make those
decisions and how we continue to have
humans making that validation.
So, this again is going to be a holistic
process. We need to kind of
come at it from like a community aspect,
right? So, don't be part of the problem.
Fact check things before we posting it,
but also like have those conversations
with people, right? Like help people to
get
the wonderful knowledge that everyone in
this room probably has because maybe we
do know a little bit more about
technology and we can help people
navigate the things that aren't true
and have those conversations. Help
grandma, help your kids. Like I have a
constant conversation with my kids like,
"Hey, do you want Alexa in your room?
Alexa can be listening to you outside
of, you know, you talking to it." Like
having a like conversations so people
can understand what they're buying into.
Um, having the conversations of
uh, like when you see something on
YouTube, like
why do you think that person is
influencing you to buy that? Do they
think they really care about you
drinking Prime and it has less sugar
than Gatorade or is it because they're
trying to sell something to you? Like we
don't want people to lose their
curiosity because sometimes that's what
saves you, right? So, being curious,
asking questions, not being part of the
problem, and really like fostering media
literacy within our community.
I know like a lot of my talks end up in
community somehow, but it's because I
truly believe that like
when you look at open source, I love
open source, and you see that like
when somebody has a cyber security or a
security issue, CVE issue
if you look at the way that they like
solved Log4j, when you have four of the
biggest companies and the smartest
people working on it, you are going to
have a better outcome than if you do it
siloed in a room with three other
people, right?
So I think that it's got to be a
holistic
um
form of
educating each other and kind of like
being good stewards
and educating
other people and ourselves. They're also
coming out with a bunch of tools that we
can use like Bot Slayer, bots, and
signal
um certified content coalition
metadata model uh
Which button?
I have no idea. Well, that was my last
slide anyways, but
thank you all for listening.