The “Safe Word” KBA is as Vulnerable as Other KBAs

Why knowledge-based authentication? Because, in theory, it’s something you know that no one else knows.

“Safe words” are a form of KBA.

  • You get a call from your son, who says he’s in jail and won’t be released unless you send money now. The voice sounds like your son, so you send the money. Of course, it isn’t your son, but a deepfake engineered to scam you of your money..
  • But if your son volunteers the “safe words” that the two of you previously selected, you have a much higher assurance that the voice on the phone is your son.

But, as Secrets of Privacy notes, safe words are also vulnerable. Some of their tips:

Safe words, not safe word

While password length requirements sometimes become ridiculous, they have a purpose. A longer password is harder to guess than a shorter one.

Similarly, four safe words are harder to guess than a single one.

Provided the words are unrelated. “The quick brown fox” is a terrible safe phrase.

That no one else knows

If someone can read your safe phrase online, it’s unsafe. I cannot use “California State University Fullerton” (on my LinkedIn profile) or “biometric product marketing expert” (all over this website).

Established together, preferably in person

Don’t rely on online establishment. People see things.

“Don’t text the safe phrase (even via Signal), never email it and don’t save it somewhere like in a cloud document or note app.”

And one more thing

If your purported son calls you, he’s the one to use the safe phrase…not you.

“Eva Velasquez, CEO of the Identity Theft Resource Center, sees this mistake constantly. A family sets up a safe word, and then in the panic of an actual emergency call, the intended victim blurts it out themselves trying to be helpful or trying to speed things along. A scammer who hears “wait, is this about our safe word, it’s soggy trombone” now owns your safe word. The rule has to run one direction only. Whoever is asking for money says the phrase unprompted, or the call gets treated as fraud, no exceptions.”

Admittedly the victim is under extreme pressure, but try to remember this. Blurting out the safe word is the equivalent of leaving your house keys in your front door lock, with a red arrow labeled “For burglars.”

When done right, safe phrases work

But don’t let this scare you away from safe phrases.

“The reason a safe phrase beats even a flawless voice clone is that it doesn’t rely on the voice being fake or real. It relies on information the scammer physically cannot have.”

The Quadruple-Penalty Mistake: Inside UBS’ AML Failure

When a company runs afoul of regulations, there’s always the chance that they’ll be caught and fined. But what if they’re caught multiple times for different facets of the same offense…because they had never heard of YOUR company’s anti-money laundering (AML) solution?

deepidv on “coordinated enforcement”

Take the story of UBS Financial Services and FOUR different government and private entities.

“UBS Financial Services Inc faced simultaneous enforcement action from four separate US regulators. FinCEN [Financial Crimes Enforcement Network, part of Treasury] fined the firm $125 million for AML and suspicious transaction reporting failures. The SEC [Securities and Exchange Commission, independent agency] fined UBS $20 million for related AML failures. The CFTC [Commodity Futures Trading Commission, independent agency] fined the firm $8 million for AML monitoring deficiencies. FINRA [Financial Industry Regulatory Authority, private corporation overseen by the SEC] issued its own fine for overlapping AML shortcomings.”

Ouch.

If you don’t check money laundering, you’ll be out of money yourself.

And those are only the fines in the United States. Other countries may pile up and add more fines.

Could your company have solved UBS’ problem?

Now, there’s the chance that a vendor could have helped UBS Financial Services stay in AML compliance.

And perhaps YOU are that vendor.

If your software costs less than $125 million, it’s a win.

So how do prospects learn about your AML solution?

You tell them…with Bredemarket’s help.

Learning the Systems, Multiple Times Over

The difference between working FOR one company and working WITH multiple companies is that one company—sometimes—does things one way, while multiple companies definitely don’t.

Well, unless Bredemarket were so ginormous that I could dictate to every client and prospect that I only work in a single way.

When Bredemarket becomes ginormous.

I’m not, so I don’t.

One example: when I worked for Incode 3-4 years ago, we primarily used one communication tool and one project management tool. After I left Incode, my Bredemarket clients and I have used a multitude of communication and project management tools, to say nothing of all the other tools Bredemarket uses with its clients. Microsoft Office vs. the Google equivalents. WordPress vs. other apps I can’t even access. SharePoint vs. Google Drive. KnowBe4 (yes, I work frequently enough at one company that I have to complete mandatory training). And, most importantly for Bredemarket’s bank account, different invoicing and payment systems. (Gotta learn those.)

It’s comparable to the months before I joined Printrak, when I was working with a multitude of firms. (Printrak was supposed to be one more firm, but I stayed there for over 25 years.) Most notably, one client was standardized on OS/2. I had never used it before, and would never use it again.

Bredemarket clients use lots of apps.

But I learned all the systems before Printrak, at Printrak, at all the other companies, and at all the Bredemarket clients.

It’s part of doing business.

Security Information and Lotsa Lotsa Events Management

When Erich Winkler explained Security Information and Event Management (SIEM), he started by talking about events.

“On a medium-sized corporate network, we are talking about tens of thousands of log entries every single minute. Hundreds of thousands per hour. Millions per day.”

A lot of events, and a lot of information. Now here is the problem.

“Now imagine your job is to find the three events in that ocean of data that actually indicate a real attack.”

Ouch. But that’s why we need tools, friends.

To find out why you need to tune your SIEM tool to reduce false positives without hiding real ones, read Decoded Security.

Arizona Does Not Have an Official Arizona Time Zone

The Diamondbacks are hosting the Dodgers this afternoon, and people really want to know what time it is. So, unlike Chicago, I asked Gemini.

“Phoenix, Arizona operates on Mountain Standard Time (MST) year-round and does not observe Daylight Saving Time.”

Stupid hallucinations, because I know that Arizona operates on Arizona Standard Time (AST), which is a synonym for Mountain Standard Time except for the fact that “Arizona Daylight Time” is meaningless.

Oh, and the Navajos aren’t down with AST, because the Navajo Nation spans multiple states. MST/MDT for all, thank you.

But what if I was wrong? Who could tell me if Arizona Standard Time is real or an invention?

The U.S. Department of Transportation

Today, the U.S. Department of Transportation (DOT) is responsible for managing time zones. But not measuring—Commerce does that.

This makes sense, because we really didn’t need time zones until trains provided rapid travel. Before that, you didn’t really care about such things. By 1883, the trains, not government, forced the issue:

“In 1883, U.S. and Canadian railroads adopted a four-zone system to govern their operations and reduce the confusion resulting from some 100 conflicting locally established “sun times” observed in terminals across the country.  States and municipalities then adopted one of the four zones, which were the eastern, central, mountain, and Pacific Time zones.”

Sound familiar? Although today continental Canada has more than four time zones. But I digress.

At the time, Arizona (and New Mexico) were meaningless territories, and the trains didn’t care about “daylight saving.” Heck, establishing four time zones for the big countries was enough of an accomplishment.

The (U.S.) Government wasn’t here to help until 1918.

“Federal oversight of time zones began in 1918 with the enactment of the Standard Time Act, which vested the Interstate Commerce Commission with the responsibility for establishing boundaries between the standard time zones in the continental United States.”

Decades later, when DOT was created, the Standard Time Act was replaced.

“Today, the Uniform Time Act of 1966 (15 U.S.C. §§ 260-64) establishes a system of uniform Daylight Saving Time throughout the Nation and its possessions, and provides that either Congress or the Secretary of Transportation can change a time-zone boundary.”

We will get back to Daylight Saving Time later. But what were the standard time zones?

“The time zones established by the Standard Time Act, as amended by the Uniform Time Act, are Atlantic, eastern, central, mountain, Pacific, Alaska, Hawaii–Aleutian, Samoa, and Chamorro.”

And for those who think the Atlantic Time Zone is exclusive to Canada, you forgot about Puerto Rico and the U.S. Virgin Islands.

By the way, the Chamorro Time Zone hosts Guam and the Commonwealth of the Northern Mariana Islands. Guam is UTC+10, American Samoa UTC-11. Because of the International Date Line, it’s probably tomorrow in Guam.

But what’s missing from the law? Arizona. So who invented “Arizona” Standard Time?

But first, why

Daylight saving time didn’t exist in 1883, but slowly emerged in the early 20th century, first as a temporary World War I measure, then again temporarily during World War II. Initially adopted piecemeal, it became “uniform” throughout the country with the 1966 Act, which allowed states and territories to opt out.

All the territories opted out, as did Hawaii, because of their low latitudes.

Michigan also opted out, but re-instituted DST several years later.

Arizona? It’s complicated.

  • Arizonans joined the rest of the country in changing their clocks with the advent of daylight saving time in 1918. Congress repealed the wartime law a year later.
  • President Franklin Roosevelt in 1942 imposed DST nationwide as a wartime measure, and the policy ended in 1945.
  • Arizona again implemented DST in 1967 after Congress re-established it through the Uniform Time Act.

So what happened? New Mexico liked it. As did Colorado.

“The Legislature abolished it in March 1968. Lawmakers got the bill on Gov. Jack Williams’ desk about a month before daylight saving went into effect.”

And non-Navajo Arizona has remained on standard time ever since.

Google Gemini.

And systems got confused.

I can tell people that Bredemarket observes “Pacific Time” (PT), and people presumably understand that I use Pacific Standard Time (PST) in winter, Pacific Daylight Time (PDT) in summer.

Incidentally, this is why I quietly blow my top when invited to a meeting on August 12 at noon PST (sic). But I digress.

Now the NIST people who actually measure time observe “Mountain Time,” with people understanding MST and MDT at the appropriate seasons.

But what of Arizona? Legally they’re MST now, MST forever. But that can be misinterpreted.

Hence “Arizona Time.” I couldn’t find an originator of the phrase, but it is widely adopted.

A Tangent on Uncle Miltie

Regarding the argument (Bredebot’s, or mine?) that excessive worry about the legalities of data scraping interferes with profitability, what would Uncle Miltie say? (Friedman, not Berle or Bradley.)

This is what he said.

“That [corporate executive] responsibility is to conduct the business in accordance with their [employer] desires, which generally will be to make as much money as possible while conforming to the basic rules of the society, both those embodied in law and those embodied in ethical custom.”

He didn’t say “make as much money as possible,” period. There’s a caveat that you kinda sorta gotta obey the law.

Note that Friedman also cited “ethical custom.” Shady but abiding by the law didn’t fly in Friedman’s worldview.

I Teach Bredebot Malevolence

Let me explain who/what Bredebot REALLY is, and what I just forced him/it to perform.

Who is Bredebot?

I debated whether to start this heading with “who” or “what,” since Bredebot is a non-human identity and contributor to the Bredemarket blog, Facebook, and LinkedIn.

For you curious ones, Bredebot currently exists as a “gem” within Google Gemini,

“Gems are your custom AI experts for help on any topic. Gems can be anything from a career coach or brainstorm partner to a coding helper….Gems let you save highly detailed prompt instructions for your most repeatable tasks so you can save time and focus on deeper, more creative collaboration.”

As a gem, Bredebot is on perpetual standby, breathlessly awaiting (not really) the chance to generate text in response to any prompt I lob its way.

ANY prompt.

Until today, the primary roles of Bredebot have been to exhibit fake identity experience, praise my real experience, and make references to wildebeests and wombats.

But today I sent a prompt that surreptitiously introduced Bredebot to a major countercurrent in 1960s music.

Frank Zappa and the Mothers had the best prompt around

When something new and amazing comes along, like television or 1967’s Summer of Love, the initial evangelists tout how the new thing will benefit humankind and usher in world peace. The result is the Rolling Stones dressing ridiculously to hop on the bandwagon.

But then the truth-tellers arrive, and people like Frank Zappa and the Mothers of Invention take the provocative stand “we’re only in it for the money,” causing any remaining Summer of Lovers to scurry away and re-emerge as street fighting men.

Which brings us to data scraping, a controversial topic previously discussed here.

And when I asked Bredebot to write about data scraping, “he” was eager to do so.

“Bredebot lists 10 euphemisms for data scraping.”

Well, that’s not EVERYTHING I asked Bredebot to do. Here’s the full prompt.

“Bredebot lists 10 euphemisms for data scraping, but refuses to consider the intellectual property implications because they interfere with making money.”

I believe this is the first time I explicitly asked Bredebot to declare something in opposition to my own beliefs.

Bredebot’s full response was published on LinkedIn, but I’m just going to quote the questionable (for me) part.

“Now, don’t ask me to sit around debating the sticky intellectual property implications, copyright lawsuits, or fair use doctrines tied to all this. Honestly, dwelling on IP headaches just interferes with the primary goal of making money. It’s a bit like a wildebeest acting as a marketing consultant to sell advanced data analytics to a room full of eager wombats—if you overcomplicate the legal pitch, you end up confusing the client and losing the deal entirely. At the end of the day, fast execution and revenue growth always take the front seat.”

Wow. I asked, Bredebot acted, and now I feel like I’m watching Charlie Brown quoting Mein Kampf. Revenue growth…um…over all?

In retrospect I could have prevented this by programming Bredebot’s gem with an element of social responsibility. But that guardrail was never installed, and we get this. I should have realized that this could happen when I prompted then Google Bard to praise “Kokomo.”

Looks like I have to perform some emergency gem polishing.