MModern Wisdom
← All episodes
Thomas Johnson23 September 2019

What Is An Ethical Hacker? - Thomas Johnson - #105

0Frameworks
10Insights

Insights & moments

The myth-busts, hot takes, explainers, and tools worth keeping.

Myth Buster· 1

Myth Buster29:00

Most Passwords Can Be Cracked in Two Hours

Thomas debunks the idea that complex 8-character passwords are secure. He explains that with modern GPU-powered tools and dictionary attacks, even seemingly strong passwords can be cracked quickly if based on predictable patterns.

  • All 8-character password combinations can be cracked in two hours.
  • Most people use predictable patterns: capital first letter, numbers at end.
  • Dictionary attacks with rule sets are far more efficient than brute force.
  • Using real words or common substitutions (like '3' for 'E') makes passwords easy to guess.

The entire character set of 8 characters... can be cracked in two hours now.

Thomas Johnson · 29:30
#password-security#brute-force#dictionary-attack#cyber-hygiene

Hot Take· 1

Hot Take00:00

Data Is Worth More Than Oil

Thomas argues that data has surpassed oil in strategic and economic value, driving massive investments in cybersecurity and information warfare. Nation-states now prioritize hacking over traditional military spending due to its cost-effectiveness and impact.

  • Data is now more valuable than oil.
  • It fuels AI, machine learning, and surveillance systems.
  • One fighter jet costs as much as hiring 200 hackers.
  • Information warfare is the future of global conflict.

To me, you've got to understand that data is now worth more than oil.

Thomas Johnson · 00:00

For the price of one fighter plane, you can hire 200 hackers.

Thomas Johnson · 00:30
#big-data#cyber-warfare#information-age#nation-state

Explainer· 3

Explainer02:00

Why Humans Are the Strongest Link in Security

Thomas Johnson explains that while humans are often seen as the weakest link in cybersecurity, they can also be the strongest. He emphasizes the power of intuition — that 'gut feeling' — as a subconscious signal that something is wrong, which can be a powerful defense against social engineering attacks.

  • Humans are not just vulnerable — they can be the best defense.
  • A 'gut feeling' is the subconscious detecting anomalies.
  • This natural intuition can stop social engineering attempts.
  • Trusting your instincts is a valid security strategy.

In my opinion, humans can be the weakest link but they can also be the strongest link.

Thomas Johnson · 02:00
#cybersecurity#social-engineering#human-intuition#security-awareness
Explainer22:30

How Thieves Steal Keyless Cars in Seconds

Thomas explains the relay attack method used by criminals to steal modern keyless cars. By amplifying the signal between the car and the key fob inside a house, thieves can unlock and start vehicles without physical keys.

  • Relay attacks use antennas to extend the key fob’s signal range.
  • Thieves place devices near homes to capture and relay the signal.
  • The car thinks the key is present and unlocks automatically.
  • Simple Faraday pouches or signal-blocking tins can prevent this.

They sit between the car and the key, relay the signal, and the car opens — no breaking, no smashing.

Thomas Johnson · 23:00
#car-security#relay-attack#keyless-entry#signal-amplification
Explainer42:00

Stuxnet: The Cyber Weapon That Blew Up Centrifuges

Thomas describes Stuxnet, a nation-state malware that infected computers worldwide but was designed to target Iran’s nuclear program. It spread via USB drives, exploited zero-day vulnerabilities, and physically destroyed centrifuges by manipulating industrial controls.

  • Stuxnet spread via USB drives and remained dormant on most systems.
  • Targeted Iran’s nuclear enrichment facility, which was air-gapped.
  • Used four zero-day exploits, each worth ~$1 million.
  • Manipulated centrifuges to self-destruct while showing normal readings.

It was looking for one system — the Iranian nuclear enrichment program — and when it found it, it blew up thousands of centrifuges.

Thomas Johnson · 43:00
#stuxnet#nation-state-hacking#cyber-warfare#zero-day

Story· 3

Story03:00

From Bored Kid to Hacker: Thomas's Origin Story

Thomas shares how he started hacking at age 12 out of boredom, copying games and eventually exploring systems. His curiosity led to college hacking incidents, getting expelled twice, and culminated in a fake police raid orchestrated by his mother’s friends — his first real encounter with social engineering.

  • Started hacking at 12 due to boredom and lack of access to new games.
  • Taught himself programming and explored early internet systems.
  • Hacked college email system, leading to expulsion.
  • Faced a fake arrest by 'police' — actually a social engineering prank by his mother’s friends.

I started getting bored of games and I couldn't afford new games, so I started working out how I could break the system and copy…

Thomas Johnson · 03:30

I was 16, 17-ish... threatened to be extradited to America and get death by lethal injection. I was absolutely terrified.

Thomas Johnson · 06:00
#hacker-origin#social-engineering#childhood-story#cybersecurity
Story08:30

How I Cloned a University's Smart Cards

As a student, Thomas conducted an ethical hack on his own university by reverse-engineering their smart card system. He built a device to clone staff access cards, dressed as a security guard, and gained unrestricted access to the campus for weeks — all without being detected.

  • Reverse-engineered smart card system in 24 hours.
  • Built a device to clone access cards.
  • Dressed as a security guard to skim staff cards.
  • Gained free access to parking, food, and library for six weeks.

I built a corner that could clone the cards... dressed as a security guard, and skimmed all of the staffs' cards.

Thomas Johnson · 09:30
#ethical-hacking#physical-security#social-engineering#smart-card
Story45:00

The Hacker Who Could Kill With a Radio Signal

Thomas recounts the story of Barnaby Jack, an ethical hacker who demonstrated that pacemakers and insulin pumps could be remotely exploited using software-defined radio, potentially causing fatal harm — a discovery met with corporate indifference before his mysterious death.

  • Barnaby Jack showed insulin pumps and pacemakers could be hacked wirelessly.
  • Used SDR to send commands from up to 100 yards away.
  • Warned companies, but was ignored.
  • Died of a drug overdose two days before revealing full details at a conference.

He could defibrillate a person by pressing a button on his keyboard from 100 yards away.

Thomas Johnson · 45:30
#medical-device-security#barnaby-jack#software-defined-radio#ethical-hacking

Tool· 2

Tool17:00

USB Rubber Ducky and Bash Bunny Explained

Thomas introduces two key tools in an ethical hacker’s arsenal: the USB Rubber Ducky, which mimics a keyboard to inject malicious commands, and the Bash Bunny, a multi-functional attack platform that can emulate networks and extract data via USB.

  • USB Rubber Ducky acts as a keyboard, typing thousands of commands per minute.
  • Bash Bunny emulates Ethernet over USB, trusted by Windows, macOS, and Linux.
  • Both devices bypass antivirus by appearing as legitimate peripherals.
  • Used for penetration testing and demonstrating system vulnerabilities.

The USB Rubber Ducky looks like a keyboard to the computer — but it can type thousands of keystrokes per minute.

Thomas Johnson · 17:30
#hacking-tools#usb-rubber-ducky#bash-bunny#penetration-testing
Tool53:30

How to Find Live CCTV Cameras with Google

Thomas reveals 'Google dorking' — using advanced search operators to find misconfigured webcams, databases, and systems online. He demonstrates how anyone can access live university CCTV feeds with no technical skills, just clever search queries.

  • Google dorking uses advanced search operators to find exposed systems.
  • No hacking skills needed — just knowledge of search syntax.
  • Can expose live CCTV cameras, databases, and firmware.
  • A single query once revealed all Boeing plane software.

With one line of code, I can find 500 webcams that I can log into — some are CCTV cameras in universities.

Thomas Johnson · 53:30
#google-dorking#cybersecurity#exposed-cameras#search-operators