How MetaCert is protecting against phishing attacks in 2020

InterviewMay 2, 202021:26

In this episode

Ashton Addison interviews Paul Walsh from MetaCert on how MetaCert is making the internet a safer place through their phishing site detection. Phishing attacks are growing in numbers during the COVID pandemic and are especially targeting the cryptocurrency and Blockchain industry. MetaCert protects teams from over 98% of phishing attacks by blockchain dangerous URLs and websites.

Key takeaways
  • MetaCert's browser extension uses a zero-trust security philosophy that verifies websites before they load, turning a shield green for verified sites and grey for unverified ones.
  • Phishing attacks have surged during the COVID-19 pandemic, with tens of thousands of new malicious domains created weekly, many impersonating Zoom and government health websites.
  • Over 90 percent of cyber attacks begin with phishing and social engineering targeting humans rather than exploiting technical vulnerabilities in computer systems.
  • MetaCert's software reduces the risk of users falling for dangerous websites by over 90 percent and takes less than 60 seconds to install across multiple browsers.
  • Phishing is the preferred attack method because compromising individuals through lookalike domains is far cheaper and easier than exploiting zero-day vulnerabilities or hacking networks.

Transcript

Read the full transcript 3,347 words, auto-generated

I'm Ashton addison from event chain for investmentpitch media and FinTech news network and today on blockchain interviews we have Paul Walsh the founder and CEO of Medicine Paul welcome to the show it's a pleasure to have you here today pleasure to be here thanks awesome likewise let's kick off the interview by giving a little bit of the background of

yourself why you're so passionate on security and how you got into the blockchain industry sure I started my tech career at AOL back in the 90s and I was part of the team that helped to launch a AOL instant messenger 56k modem protocol and some other cool tech back in the 90s then I worked in the mobile industry for a while started my first company in 2003

and from an industry perspective I've contributed to a number of industry standards and best practices so I'm one of the seven original founders of the mobile web initiative at the w3c which is the standards body for the world wide web that creates standards like HTML and I also am one of the two people that Co instigated the standard for URL classification and content mingling and

more recently founder and CEO of medicine which is a cyber security company and the way I got into blockchain was in 2017 a few crypto companies reached out to us and said hey Paul you seem to be the only guys that have a security integration for slack were being absolutely hammered by phishing scammers on slack can you come in and take a look at it and so we did

we ended up iterating the product because the bad guys were doing things we couldn't have dreamt of and it was truly a massive phishing epidemic on slack for the cryptocurrency world for everybody worldwide and so we ended up having herself were installed by almost all all crypto companies on slack and we just eradicated phishing on slack back then and that's how we got him to

blockchain and crypto so it was June 2017 is when we got to the space wow that's great Paul and our slack channel was also affected in summer of 2017 from fishing and it was widely known so it it's great to great timing for that application and the fishing seems to be continuing on now that these pandemics are growing the use of Internet communications but well dive

into that in a little bit here but if you could just give a little bit more of an overview of metasearch and not just the slack integration but the full application and also you know how is that specifically making the internet a safer place sure following on from what we did on the slack platform we came to realize that it didn't matter how big or how

good our database was in terms of classifying dangerous websites such as malware and phishing because there's always going to be at least one victim before you can protect other people because it's mathematically impossible for any security company to detect and block every new dangerous link or every new counterfeit dangerous website so it's mathematically impossible and we

were just so frustrated by the fact that people were losing their entire life savings or companies were being breached and so we went on this path to see if we could find a zero sum or history is zero victim solution and we came up with this social experiment in December 2017 and that is now what is the led to our flagship product which were 100% focused

on which is basically a different way of looking at cyber security and the strategy or philosophy is called zero trust and that basically means that you assume everything is dangerous unless it's verified so as you know it's not dangerous and that comes in the form of browser extensions so we have a browser extension that supports brave Firefox Chrome and opera and soon Microsoft edge

and it takes less than 60 seconds to install and it does two things firstly it does what every other security company on the planet test which is it blocks known dangerous websites and links but then the main utility that we focused on that no other company does is anytime you open a link whether it's inside slack or telegram or your email or your presence in the web

it always opens in the internet browser so what happens is when you open the link before the webpage has time to load it checks medicine to see it's verified or not so let's say you're opening a link to zoom or a link to a covert 19 news article or a government website or you're signing into Microsoft 360 finds it checks medicine and when it's verified the shield that we install in

your toolbar turns from grey to green and therefore you know you're really on the right website now if the shield doesn't turn green for a popular mainstream website and it remains grey and it's not blocked then you know it's possibly a new threat that has not been detected by anybody at all so the grey shield is pretty magical in that regard and we've verified millions

of websites and sign-in pages and so so far we haven't had a single victim of 18 this link or a phishing website when protected by medicines Wow very impressive and it's great that you have the compatibility across all those web browsers and so with this pandemic I've seen articles about there's more malware and phishing attacks that are

targeting North Americans more than ever you know have you seen this and has your company had to respond to this activity yes we have seen it in fact I'm on the committee for what is called the covert 19 cyber threat coalition and it's made up of 3,000 cybersecurity professionals from around the world these are security professionals that work for security

vendors friends government agencies law enforcement and so on and the task of that coalition is to do one thing that is to create a repository of known malicious links and websites and IP addresses and other vectors that are specific to covert 19 so it's absolutely gone through the roof we're also saying not only our remote workers being targeted because they're

working remotely where they probably have less security but also they're being targeted with covert specific scams and fraud whether it's you know a website pretending to be the World Health Organization or it's a news website or it could be a pretend government website saying that they've got free tests but then also we're now seeing a huge uptick in the number of

phishing websites made to look like the Xoom website because the bad guys know that most people now are kind of concerned for their well-being they're concerned about the pandemic but they're also using zoom quite a lot so there's a huge number I mean we're talking about many many tens of thousands of new fishing domains covered related specifically every few weeks Wow a bit

vague saying tens of thousands and every few weeks because you know we could see 50,000 in one week so yeah it's it's huge and medicine obviously has suffered badly because of covert 19 just like every other business but in a sense it's good timing because our software is designed for end users so it's perfect for remote workers and it reduces the risk of anybody falling

for a dangerous website by more than 90 percent and I saved 98 percent because no software application and no human is perfect so we say 98% so it's perfectly positioned for people who work from home because it literally takes 30 to 60 seconds to install and it just works out of the box and importantly it's designed for humans whereas traditional security

solutions are mostly designed for computer systems and computer networks but what we know is that over 90 percent of all cyber attacks started fishing with as people it's humans being targeted with what's called a social engineering and so our software is specifically designed for humans that's great Paul and I'm interesting that you mentioned about the zoom you know we've seen zoom

bombing and the fact that there may be privacy concerns with zoom but I hadn't heard of phishing attacks in you know downloading fake versions of zoom or impersonating the website so that's really interesting to note and there's so many of these different phishing attacks that it's just hard to keep track which is why we need metasearch and to touch on phishing a little bit

more could you explain why has it become the most popular way of targeting people because there are so many different ways that cyber hackers are looking to hack into people's data and their computers sure it's pretty straightforward actually it's a lot easier to compromise a person with a lookalike domain or a counterfeit website than it is to try and take advantage of zero-day

vulnerabilities so trying to hack as a computer system or a network is far more expensive time consuming and more difficult than looking up specific individuals to see what their position is by looking at LinkedIn see what data they probably have access to and then target them with a spear phishing attack and that's how over 90 percent of data breaches and cyber attacks happen it's

not just on consumers it happens in most most cases when you hear of personal records being stolen like for example a Microsoft employee who works on Microsoft 365 was targeted and compromised in a phishing scam and the bad actors then once they had access to his systems they had access to their customers and so they targeted all of

Microsoft's non-paying customers with phishing scams so that they could actually steal the cryptocurrency so while most people don't realize is when you read in the media or somebody has had their crypto stolen they don't often realize that it actually started with a very sophisticated targeted attack on the company that they use or on a supplier that they use mm-hmm Wow and that was

going to be my next question about crypto currency there's a lot of people who have been holding her poo currency for a few years and understand that you know people that are holding their own private keys on their computers or offline there's no other counterparties if they lose that crypto currency if they happen to get scammed and I think I've seen not just wallet websites but

exchanges in the like all you know trying to impersonate to dupe cryptocurrency users is that have you seen a lot of that as well oh yes and if you saw the number of domains that we've classified as phishing for my ether wallet or my crypto or finance it would blow your mind you're talking about thousands and thousands for each of those websites so you know it's like

playing a game of whack-a-mole once you block or take down one phishing website ten or a hundred more pop right back up which is why our software focuses on telling you what's safe and in fact actually we unfolded the most sophisticated phishing scam I've ever seen in my entire career and it just happened to be in the crypto world which was a vet with a blockchain company and

its fact that the founders of the blockchain company are amongst the smartest that I've ever come across they're Russian founders very technically competent and they almost fell for phishing stone but they were using medicine because I'm also an advisor to their company and what happened was these actors started to like their posts on LinkedIn and he

started to engage with them then he started to reach out to him pretending they were from finance saying oh you look like you have a great project we want to look at this as a potential investment opportunity so they took the conversation from LinkedIn to telegram and email and after a couple of weeks they said okay this looks great we want to invest in your company

but first you need to send us three and a half Bitcoin for upfront marketing commissions and then we will invest $500,000 when they went to click on that link they realized that the shield was gray and for a buying announced website you would definitely expect that to be green and then they reached out to me I reached out to finance and the finance

guys came back and said yep this is definitely a phishing scam and as a direct result of that they set up a private telegram group just for the security team at finance and medicine to collaborate and make sure that we always verified their new domains that they come out with in the future so that was a that was a tarp very highly sophisticated targeted attack in the

crypt of the world that was fortunately kind of stopped but that happens every day of the week whenever you hear about a breach or a loss sort of an exchange or a wallet the chances are that unless it specifically says that there was the vulnerability somewhere the chances are it was a phishing scam and that employee fell for the phishing scam and then the

bad actors had access to other internal systems so crypto companies unfortunately don't I mean finance my crypto my you throw a wallet are pretty mature in the crypto world so their security practices and their security personnel are are proficient but for the best part a lot of companies don't actually tend to focus too much on security and they think that they're safe and they assume

that the only phishing scam they'll ever see is crypto or related but it's not what it could be is a password reset for Apple iTunes it could be a fake facebook login page and then once the bad actor has access to those details the chances are that employee uses the same username and password for other internal systems and then they go off and they try those

credentials and until they find that they've got access to sensitive information mm-hmm it's a great backstory and just shows the lengths that these criminals can go to to target you know high-level scams so that's really interesting I guess one of my last questions would be you know there's a lot of North Americans that aren't using cryptocurrency or they

don't consider themselves to be power users of computers and maybe they feel like they don't have anything to hide or they don't really have anything to lose what would you say to those average users on the computer that you know they they actually do have something to lose we all have something to lose because you may not necessarily be targeted with

an attack but they I forget the statistics right off my head right now in terms of the number of emails that people receive and dangerous things today click on but you know whether it's spyware around somewhere malware over 90% of those actually start with phishing so phishing is not what a lot of people think it is it's not just the theft it's not just about encouraging people to

give away their personal details it could actually be the installation of malware right now hotel or hospitals are being attacked with ransomware attacks even though covered 19 is a serious problem with that guys don't take time off and it's almost always a phishing attack the state-sponsored attacks on the US government are almost always phishing attacks like the Hillary

Clinton email problem that was a spear phishing attack on one of her employees so for the average user I would say I would give a few tips actually actually if you don't mind yeah and to go back to one of your questions is why is they targeted people so most people have been conditioned to look for the browser padlock and then they automatically assume that they're on the right website

because you know HTTP and the padlock means I must really be on Dropbox that's not true it just means it's encrypted it just means you've got a private connection between you and either Dropbox or potentially the devil so over 93% of all new phishing sites have the padlock you can trust pup and when you're in an email hovering over a link doesn't help

because it doesn't tell you the actual destination it just tells you what the first hop in that jump is so could redirect multiple times checking to see if the senator is the real person but you think it is that's important of course but doesn't always work because it's easy to make an email look like it comes from Apple the Apple business team for example telling people to know the

open emails from people they don't know or don't click on links from people they don't know that advice doesn't work because we all have told makes from people that we don't know or we wouldn't be able to do our work so just be just be aware of that when it comes to mebut our software is $2.00 19 per month and how we give us a significant discount if

you pay within the first 24 hours so if you have anything that's worth more than $2 19 a month then it might be worth to install it if it's not maybe maybe not but an it I'm not here to page Meta Search I'm really passionate about protecting people from dangerous links and dangerous websites and quite frankly telling you what's safe it really is the

only way to protect people because trying to block dangerous websites and dangerous links obviously isn't working because cyber security Expenditure cyber security investments into new technology is at an all-time high it's increasing all the time but then summer cyber attacks and so something is obviously not working out here for us as an industry if we're pumping more money

into cyber security technologies and companies are paying more for those technologies why are the cyber attacks still happening why are we reading about data breaches and personal records being stolen every second of every day so stay vigilant and just kind of don't be too quick to click on things thankfully the days of 2017 where crypto companies were sending out emails and

telling people to click on links within seconds or they lose out on a discount thankfully though those days are behind us because the FOMO that fear of missing out is one of the biggest reasons people click on links with him the crypto world if they're being offered a discount they can't you know refuse so yeah just being vigilant about time and anything that

says you need to do this fast that's when you slow down even more yeah great points Paul I will leave the information to medicine in the description box below for the viewers if they are looking to follow along to get more security advice is there a way to connect with you or follow along with your work sure Medus or comm is the website telegram group where we engage with our

community the telegram group is T dummy slash Minister my Twitter account is a little bit more difficult to find because it's Paul underscore underscore Walsh and the story behind that unusual name I'll say for when we meet in person haven't gotten swine together that would be great thank you so much Paul it's been a pleasure speaking with you and thank you for all the information for

all these people that need to stay diligent in these crazy times and let's follow up in the near future and see the growth of medicine I look forward to it thanks so much nice to keep safe

More interviews

Browse all 1,089 interviews

Get new interviews firstThe BlockWest newsletter: markets, AI and policy, twice a week. Free.

Subscribe free