Potential Dangers of ChatGPT – Mark Kapczynski, OneRep
Mark Kapczynski, SVP of strategic partnerships at OneRep, a company that automates the removal of unauthorized private listings from the web to help people restore privacy, dives into this topic more, how ChatGPT can be used to write code that steals data and why it has the potential to take social engineering scams to the industrial level.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with Mark cabazinski senior vice president for strategic Partnerships with one rep and we're talking about chat GPT. And one of the bad guys have figured out how to make this thing work or not Mark welcome to show. Thanks for having me Michael.
Appreciate it. All right, we have for the last several months been treated to all kinds of claims that the sky is falling in. The bad guys are gonna use Ai and our world will be unrecognizable and we won't be able to trust anything in whatever and we all know the story and that's different that's different from today.
Yeah, exactly. The question I have is are we actually seeing this to the bad guys gonna make use of this because on the other end of it. I've seen some of them start the complain online that the code that this thing generated is doesn't really work in the malware that they're using and they're like, yeah guys, this is nearly as good as we had hoped.
Yeah. Know I think there's a like questions obviously pretty broad. Right and there's a lot of different factors in this and you know, unfortunately when you're doing with trying to figure out a fraudster, you got to think like a fraudster and so, you know, it starts by having different bits of information and you know, so like I guess what I'd say is is on the good side chat GPT and a lot of the AI isn't just giving up personal information, you know, so like if you say put it to chat GPT, like tell me all about Mark capsinski.
It'll only share at best some like personal public information like my LinkedIn information at best most of the times it'll just say I'm not chat GPT isn't available to provide personal details. And so there's some like natural defenses there for this, but certainly that won't stop the fraudsters and a fraudsters goal is to To learn enough about you so that they can either con you directly or cheat some other system commit fraud against another system. And so for that they still have to rely on some of what I think of as more though, like Legacy tools which are sadly are things like the dark web which I don't know if you're familiar with that but it's you know, where they typically get a list of names and maybe some credit card numbers or driver's license numbers and that usually becomes their starting point.
Unfortunately for them. I guess they can't commit a lot of fraud just with like a name and a number they need more details about that person. And so again, this is where you know using a tool like chat GPT to try to find out information on me isn't gonna give them enough detail for them to cause real fraud and I guess I'll say yes right in time.
I'm sure you know as things get more open. And chat GPT or other AI platforms expose more personal information. That's when it really gets scary.
And so so what ends up happening with fraudsters today is they use the dark web is like their you know Source or you know source of Truth in the data world the sense and then what they try to do is fill in the rest of the details around that person's name. So again without having like an actress it's hard for them to commit a lot of fraud. So the first thing they got to do is okay Mark kempsinski.
Where's he live? What's his address? How do I get that?
That's where they go to these what I think it was pretty nasty sites called people search sites where so if you've ever Googled a person's name, you'll find them predominantly listed there. And those are sites where they can literally for like 10 20 dollars a month have unlimited access to personal information. And so that's where they're taking the first little bit of data that they have and now enrich It with a little bit more data and that starts to enable them to commit fraud.
So chat GPT is really on the personal side. I think it's going to be limited. Now what you're what you were that actually brought up was like can they use it in essence from a software standpoint?
And I think that's actually where you will see some opportunities because fraudsters. Well, you know, they may seem sophisticated, you know, they're it's not like an IT department or a tech, you know, Dev team, you know that has rigorous code, you know design and check-ins and QA and so, you know fraudsters just need enough to be dangerous, right and a lot of things that they need. They don't really need highly sophisticated code.
So to to say try to create a credit card Or to try to create a you know, a credit file request or open a bank account for that matter if they have dark web data. Plus people search data, then the kind of code that they will need is automation code. So they need to be able to take lots of names with lots of details and be able to process through that to test which combination is actually going to work to get them through the account opening process whether for credit card bank account Etc, then that's what ends up enabling them to commit the fraud.
So the way I would think of it is chat GPT code to produce some automated test harnesses probably good enough. Chat GPT to find personal information and you know commit serious levels of crime probably not there yet. Do you think though that as people realize that their data is being scraped for these AI engines that people are going to be more careful about what data they expose because historically and we seem to just share everything and anything and it always up in the dark web somewhere and nobody seems to think twice.
Yeah, sadly, unfortunately, no and it's not even just the dark web because dark web data typically has been data breach or hacked people give out their personal information every day to you know, log into a news site or to watch a movie trailer or sign up for a contest all of that data ends up showing up on these people search websites. So, you know people day to day activities are actually in some ways more dangerous than worrying about if your data shows up on a data breach and shows up on the dark web. So the real behavior that has to change is don't give out your personal information for like what's Games like the most harmless thing like, oh, I just need to give them my name and information for a coupon or for, you know, some lead genocide or you know log into see movie trailers or you know, subscribe or enter a contest.
Those are things that are actually more dangerous because that stuff is you know for lack of a better term legal right I've opted and I've given the site that information. I I've in essence agreed to the terms and conditions and privacy policy of that data and typically those sites have the rights to what's called sell that data or even enhance or enrich that data so they just pass it along the chain to larger data Brokers like You know the credit bureaus like Transunion and LexisNexis who can then pull in thousands of different data sources. Package it all up.
You don't even know where it came from at the end of the day and then they sell it back out to people search sites and other companies that you know, then like I said for $20 a month can enable a fraudster to have full access to you know, the entire database of adults in America. So what do we need to do to kind of prevent that because you would think that by now all the companies that are victims of these broads whether it's a healthcare service or a financial services company would be screaming their heads off about this. Yeah, well, you know the you know, when you're trying to prevent fraud it's not a obviously an easy thing and it's not a one thing like oh, I put the lock on it and we're good.
Right and so it's it's about having a web of different things. And that's where I think protocols have gotten better and the webs to try to catch fraudsters have gotten better, you know, you know companies I've worked with previously, you know, the webs that we would create would give like false positives. So a hacker or a fraudster with think they've got the right pii personal identifiable information to pass through a sequence something known as like out of wallet questions, which is one of the bigger blockers, you know, the things where it's like did you own this house this address or did you own this car things that only you should know broadsters have to get through that that's why they need all this extra pii and so what a lot of techniques That are in place today are you know provide false positives?
So the hacker thinks they got through a level, but then they're in just kind of like a honey pot that they're trapped to try to prevent fraud. So things are getting better, you know, the real piece I think in all this is just more and more consumer education that you know, you can't just put your personal information out there and you know, maybe the real opportunity here down the road is, you know, people should have more caught synthetic identities that are used to surf the web versus, you know, just Me giving out my personal name and home address. I mean, that's the scary stuff to give out.
Right so I can have six or seven different online personalities and really get schizophrenic if I want it but the very least you would never know which one was the real me, right? Yeah, you know it's funny. My boss had experience a great guy.
He he would always have a different sequence of of caught pii that he would use when he was filling out forms on the web like man, how do you keep track of all that and like he had a little formula in his head basically that he had built out on how to put in different bits of personal information and he mentally could track back like so if he ever saw a certain spelling or a certain address he knew where it came from at the end of the day and obviously can't expect the average consumer to do that. But that's the kind of identity management technology that we really need to make it such that it consumer and enjoy all the great things about the internet but not expose themselves. That's really a big piece.
And if I can also add the biggest thing that I think and almost immediately be done as all this. tool information like I guess two things that should be done one is Personal information should not be easily bought and sold between companies like that has to stop like that can't be allowed. The second thing is if that information my personal information is published on Google it or in a way that Google can index it that cannot be allowed.
Like how is it fathomable that Google can index my home address my family members and such off of these nasty people search websites and get away with it like that has to stop right away. Part of the issue also seems that we're not Savvy of when we're giving up that personal information because it's one thing that fell out a form to get a service but it seems like folks are also you know, they're taking surveys online and that says you know, what kind of car did you have when you were 18 and where did you when you were 27 and that's all information that the bad guys are using for fraud right? That's right.
Correct. And they said the bad guys know that they need all of these different bits of information. And so they use a number of different tools Technologies and services to go find it but it's all out there.
Do you think at some point AI might help us discover defend ourselves against this because if the bad guys are using it, it should be a tool that cuts both ways and maybe we could figure out a way to manage that fake identity process you were talking about. I mean, we kind of use some people use it for junk mail today. They already know who sold their job mail address.
So it's the same idea, right? Yeah, absolutely. I I do think you know artificial intelligence can can help us and it'll I think get better at like fraud prevention, right?
So it'll help Drive automation of creating these webs and honey pots to catch the bad guys. So I think if anything will be used more widely to catch the bad guys and maybe the bad guys themselves trying to use it. I think I think chat GPT and AI will have that bigger advantage on I'll say our side versus the bad guys side at the end of the day at least I hope So what's your best advice to folks that we need just better regulations and we need to call our local Congressman or is there something else that we should be thinking about?
Yeah, I mean sadly, you know, I'm not a always a huge proponent of getting the government involved in things. But in this one particular case, you know, I always joke like the US is a unique entity or a unique country in that where the only ones that doesn't have a national or federal level privacy policy and protection of your personal information, you know, the fact that it's so easy for companies to buy and sell my personal information and I can't do anything about it. That's really atrocious.
And so I do think we do need a federal level privacy protection policy that forbids companies from buying and selling personal information so easily and then I think again I go back to the second thing is Google should not be allowed to index my personal information. Like Google is basically putting Me In Harm's Way. Has anybody calculated how much we're spending on security to make up for the fact that we're not protecting data in the first place?
Yeah, it's always funny right because people spend so much money on security when you know, sometimes the easiest thing isn't even this, you know isn't even to try to defeat the security. Right? It's the social engineering stuff that makes it even easier right if you in in our world with, you know online account opening and things like that if you can get through out of wallet questions, you can open a credit card account.
You know, so if I have your name and social security number from the dark web through a data breach and then I can marry it up with like the information about where you live your address and I can get enough details about you about your you know, address history car history Etc. I can get through out of wallet questions. And then that means I can open a bank account or a credit card account and then you know, the problem with all of this too is the way frosters work.
You know, I guess it gotten smarter is they don't just once they open the credit card use it right away. They sit on it and and wait and they eventually test it. They test it with online services to see if it's a good card to use and not gonna have any issue and then they wait even longer and then they have what's called a breakout where they'll go, you know rack up the whole card, you know, five $10,000 worth of credit on it by a bunch of stuff and then disappear.
and so that's the problem is like You know, your information could be all out there. You think you're safe and fine. You're doing everything you can you think to protect yourself but like You know two years down the road someone could break out and already have.
You know committed fraud against you never know it. All right, folks back in the battle days fraudsters went to the graveyard tried to figure out who died and used those IDs now, it's all just a Google search away. I guess that's progress for somebody, but maybe not in the right direction mark, thank you.
Thanks for having me on. That and back to you guys in the studio.