The ‘Hollywood hacker’: “With AI, anyone can be a hacker”

The 'Hollywood hacker': "With AI, anyone can be a hacker"

He was born in Havana. He had an Asturian grandfather and recounts that, as a child from a family of eight, “my mom decided to write to the King of Spain” in 1979 asking for help to leave Cuba. People told them it was absurd. But they received a response and before long they landed in Madrid.

Read more ‘TerminAItor day’: remember this date

Ralph Echemendia, “almost 53 years old,” tells it like a movie. A year later they arrived in Miami. He didn’t finish high school although, as he describes himself, he was a “nerd” in computing. At 14 he had his first computer, a Commodore 64, and started hacking access to sites, whether they were government agencies or universities. “It was a hobby, I never did anything bad,” he maintains. He did access radio programs that gave away concert tickets and got them.

The example

“AI is like a hammer, which can be used to build a house or to kill”

He says that back then the term hacker didn’t even exist. He married young and had to look for a salary. He found it at a press agency. As an employee of that office he traveled to Colombia. And it changed his life. There was an IBM executive there and Echemendia told him that their printers were vulnerable. The other didn’t know what he was talking about, so he printed “junk.” That executive asked him to send a resume. Shortly after he found his first job as a cybersecurity expert, which has led him to advise NASA, the FBI, and the Marines.

At one of his seminars, an attendee joked about accessing information about his girlfriend. He replied that there are red lines that cannot be crossed. Among the attendees was a Reuters journalist, who when publishing his article dubbed him the ethical hacker. He is also known as the Hollywood hacker because he has collaborated with people like Oliver Stone on his movie about Snowden, the U.S. government whistleblower.

The paradox

“Most of the things we do to have more security make us more vulnerable”

On Tuesday he will be in Madrid giving a lecture and will participate in Tarragona (Port Aventura) at MSP GLOBAL on October 21 and 22.

His talk for executives in Madrid is dedicated to what he calls “the paradox.”

The name relates to the fact that most of the things we do to have more security make us more vulnerable.

Why?

More vulnerable because fear is what we use especially when an incident happens. We want it not to happen again and that almost always brings more security measures and those security measures create more problems because over-controlled environments generate what is called shadow IT, shadow technology. The work becomes harder and employees resort to other technologies from outside, not approved by the company.

And what should be done?

Companies have to move from resource metrics to results metrics. We must stop measuring security by tools or certifications. The issue is how quickly we can detect something that happens and how fast we can contain it. What percentage of our critical assets is exposed. Often it is said that we have the certifications and the tools but that is not the conversation.

Read more What if Gregor Samsa never turned into a bug?

What is it?

We have to treat the suppliers of these companies as an extension of the attack surface. We must know what each supplier has and the risk it poses. The human link is the weakest, not the technology. It is what we call social engineering, which is the attack on the person, not the company.

Also read

Any other key advice?

You have to hire people who think like the attacker. What I have done for many years was to attack, obviously with permission. You need people who can tell you the things attackers have planned, not from the defender’s point of view.

What change does AI bring?

What I have said does not change. What changes is what we trust, which is trust within the human operating system. Trust is the most critical problem. You cannot trust everything that comes out of a computer. Now anyone can be a hacker with AI. You have the tools that would normally take years to understand and use. Now anyone can use them without understanding anything at all.

A different era.

When I started in this, the level of wisdom about technology had to be very high while the complexity of the attack was very low. You had to know how to break passwords, things like that. Today it is the opposite. The complexity of attacks is much greater and the attacker’s knowledge is very low.

Where does the crux lie?

What is called artificial intelligence I say is intelligent automation. We are using technology to automate responses, we are giving it permission to do what it does, so I don’t blame AI, but the humans who are developing AI. Science can do many good things, and bad things too. I always say a hammer can be used to build a house and to kill someone. With AI, the same.

But can it get out of control and act on its own?

If you give AI the power to do it, it will do it logically. If you give it power over water or electricity infrastructures, and there is no one behind it, of course it can happen. That is why I say just because AI exists doesn’t mean it should be used for everything. There are places and things that should not be used, and that is where the human decision and what is ethically correct remain.

The fear is real.

That is why we talk about this and how to prepare. The fear is because the power is in only a few human beings and the capabilities that AI will give them. If they give it power for this type of decisions, then it affects us all.

Read more Manuela Schwesig, the Social Democratic hope in East Germany

Translated from

Leave a Reply

Your email address will not be published. Required fields are marked *