Despite the Friction, I Read This Message Anyway. And Wished I Hadn’t.

I simplified my social life a few months ago by no longer posting on Instagram. I don’t even have Instagram on my phone any more.

But Instagram Meta-relative Facebook is “nice” enough to inform me when I receive Instagam messages, as well as unsolicited Instagram message requests. Which I obvously can’t read on my phone (in part because I also removed Meta for Business).

Joining the “brand ambassador” inner circle

So one day when I happened to be on my laptop, I brought up my Instagram account. I wanted to see the latest message request, reportedly from “Navin Nandra”…even though I already knew it was in a languge using the Cyrillic alphabet. And probably wouldn’t bring Bredemarkeet a ton of business.

So here’s what I had to do:

  • Go from my phone to my laptop.
  • Log in to Instagram.
  • Find my message requests.
  • Translate the message request that I received.

After translating, I was right in guessing that this was a waste of time. Here is how the message began:

“Good day! This is the brand manager for the clothing brand PRIME Wear

“I’m messaging you from a tech/alternative account—we use these to avoid getting blocked by Instagram Direct limits.

“We absolutely love your style and the content on your blog!

We would love to invite you to join our inner circle of PRIME brand ambassadors.”

Um, no. These “we love your style” messages are always amusing to me. Especially when account number one tells you to contact account number two. Because reasons.

Google Gemini.

Yeah, “ambassador.” My last name isn’t Jenner, and my look isn’t Jenner either.

Google Gemini.

The underlying scams

So I asked Google Gemini about the scam behind these amazing offers, because I suspected a scam. To please me, Google Gemini said that there are scams related to this. I could have fact-checked this on a live web page, but I had already wasted too much time on this.

Here’s one of Gemini’s reported scams:

You are told you have been “hand-picked” to represent the brand. They offer to send you jewelry, sunglasses, or clothing for “free” so you can take photos with it.

  • The Catch: They give you a discount code that brings the item’s cost to $0, but you have to pay $10 to $15 for shipping.
  • The Reality: The brand is usually a front for a dropshipping operation. They buy the items from bulk wholesale sites for less than $1. Your “shipping fee” actually covers the cost of the item and gives the scammer a profit.
  • The Outcome: You paid full retail price (or more) for a low-quality, cheap item, while giving them free advertising.

Bad enough, but it could get a lot worse.

Some requests are much more malicious. A “talent scout” or “brand manager” will message you offering high-paying sponsorships ($500+ per post), even if you only have a few hundred followers.

  • The Catch: To “set up the partnership” or “verify your account,” they send you a link to a portal or ask for your 2FA (Two-Factor Authentication) code.
  • The Reality: The link leads to a fake Instagram login page designed to harvest your password. If you give them a 2FA code, they will immediately change the email associated with your account, lock you out, and hold your account hostage or use it to scam your friends.

So “Navin Nandra” is now blocked. And I can avoid Instagram again for a while.

Even Jedis Can Face Ephemeral Challenges

From a recent Identity Jedi post.

“NHI visibility and AI agent visibility feel like the same problem. They’re not. A service account is relatively static. It was created for a purpose, it has credentials, it authenticates to something. You can find it, document it, rotate its credentials, put it in a vault. That’s a solvable problem with existing tooling.

“An AI agent is different in almost every dimension that matters. It’s dynamic. It’s often ephemeral. It doesn’t have a fixed identity. It borrows one, or several. It makes decisions at runtime about what it needs to access. And it operates at machine speed, which means by the time your SIEM fires an alert, the transaction is already done.”

The Continuing Adventures of Will and Chad

Technically Chad Smith engaged in identity fraud on Saturday Night Live when he started giving Will Ferrell’s monologue.

But no harm was done.

And while the face modality fooled many of us, the voice modality gave Chad away. Score one for multimodal authentication.

Non-Human Identity Verification

How do you verify non-human identities?

One of the reasons that I titled my ebook “Proving Humanity” is because the six (yes, six) factors of identity verification and authentication that I discuss only apply to identifying humans, and do not apply to non-human identities.

Again, so how do you verify non-human identities?

Cryptographics

One way is via cryptographics. As I discussed previously, the Secure Production Identity Framework For Everyone (SPIFFE) and the SPIFFE Runtime Environment (SPIRE) provide non-person entities with “strongly attested, cryptographic identities.”

Problem solved, right?

As any human who has used a password knows, a single factor can be stolen. And that includes cryptographic factors.

Provenance

Which means that we have to look at provenance. But instead of looking at the provenance of an AI-generated image or video, we are looking at the provenance of an agent that performs actions. The network origin. The environment. The associated attributes. Is the agent running on a specific, authorized, and known virtual machine or container at a specific network address, or is it running…somewhere else?

Behavior

And if you’ve read my book, you know that human identities can be evaluated based upon their behavior (either tendencies or intent). You can also look at the behavior of agents. Is the agent acting at an unexpected time of day? Is it executing an unusually high volume of requests? Is it “scoping out the joint”?

Multi-factor authentication

Again, it’s possible to spoof one factor, but much harder to spoof multiple factors. And that applies to both humans and non-human agents.

Be safe out there.

Proof of Humanity Does Not Prove Identity

If you have a database of people worldwide, you can use irises to see whether someone is in the database or not.

This lets you buy the world a Coke. One per person.

But it doesn’t tell you WHO they are.

For that you need to test them against the factors of identity verification and authentication.

All six of them.

Learn more. Purchase the ebook.

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket. Click on the image to purchase.
Proving Humanity: The Six Factors of Identity Verification and Authentication.

Factors Are Independent

One important thing about factors is that they are independent of each other.

The fact that a person has a particular password bears no relation to the fact that a person has a particular fingerprint ridge structure.

And even modalities within a factor may be independent of each other. When Motorola sold its Biometric Business Unit to Safran in 2009, I joined a company (MorphoTrak) that promoted three biometric modalities: finger, face, and iris. While all three biometrics came from the same person, there was no relationship between any of them. Knowing a person’s right forefinger did not tell you what the person’s iris was like. (But beware: driver’s licenses and passports share information, such as dates of birth.)

If you have a critical security issue, you don’t want to depend upon just one factor, or one modality.

Double or triple them up by requiring multiple identity verifications and authentications with unrelated modalities and factors.

Learn more about the six identity factors

Six identity factors. One Bredemarket ebook. Total identity protection. Purchase “Proving Humanity: The Six Factors of Identity Verification and Authentication.”

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket., Click on the image to purchase.

Why Are Identity Verification and Authentication Critically Important?

Imagine if we didn’t have identity verification and authentication.

I could walk into a luxury car dealership and buy a car, telling the salesperson that my name is Bill Gates. I could buy the car, and Gates would get the bill.

Sounds great…until someone impersonates YOU and gets YOUR money.

Learn more about the six identity factors

Six identity factors. One Bredemarket ebook. Total identity protection. Purchase “Proving Humanity: The Six Factors of Identity Verification and Authentication.”

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket., Click on the image to purchase.

How to Figure Out Someone’s Mother’s Maiden Name

Something you know…and that someone else knows. It can happen.

Many systems require more than one knowledge-based modality, which is why they sometimes ask for other things like your mother’s maiden name.

This of course is not foolproof. Your sister that hates your guts, for example, obviously knows your mother’s maiden name. And even complete strangers, especially those with nefarious intent, can deduce your personal information.

Let me introduce you to Doug.

How Doug learned Donna’s mother’s maiden name…and more

Assume that Doug wants to hack Donna’s account but needs some personal information to do so. This is somewhat tough, since Donna’s Facebook account is private and can only be seen by her friends. Well, Doug knows that Belle is a friend of Donna’s, and Belle’s Facebook password is “password1.” Problem solved.

Doug uses Belle’s account to read Donna’s posts and finds some remarkably interesting ones. Not that she’s posting her Social Security Number or anything, but what did she post?

  • “Happy birthday to my mom!” (This particular post was loved by Jane Davis, who wrote “Thank you dear daughter.”)
  • “Happy 30th birthday to me!”
  • “Hey, look at this picture of my new driver’s license. My picture actually looks halfway decent.”
  • “Hey, look at this picture of my senior citizen bus pass. Yeah, I’m old.”
  • “I cried when I looked at this old picture of my dog Scamper, taken in front of my childhood home on Mulberry Street.”

If you’re keeping score at home, Doug now knows the following information about Donna:

  • Her mother’s maiden name.
  • Her date of birth (from her birthday post and her driver’s license picture; her senior citizen’s bus pass doesn’t have her birthdate but does have her birthday).
  • Her driver’s license number.
  • The name of her favorite pet.
  • The name of the street she lived on as a child.

More than enough for Doug to impersonate Donna.

Learn more about the six identity factors

Six identity factors. One Bredemarket ebook. Total identity protection. Purchase “Proving Humanity: The Six Factors of Identity Verification and Authentication.”

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket., Click on the image to purchase.