ChatGPT poses serious security risks; ditch passwords
THE ChatGPT craze has swept the world. Within just a few months of its release, the artificial intelligence (AI) chatbot app has reached 100 million active users, making it the fastest-growing consumer application ever launched – surpassing even social media platforms TikTok and Instagram. What’s more, Google, Microsoft, and Baidu have also announced plans for AI-enhanced search, taking the AI space race into a new phase.
While many have sung praises about its benefits (including the ability to parse through data noise to find sophisticated attack signals), cybersecurity experts have also warned that the increasing use of such AI-powered technology comes with risks – and could facilitate the work of scammers and cybercrime syndicates. With phishing scams in Singapore jumping 41 per cent from year 2021 to 2022, how much more risk can chatbots pose?
Gearing up for the AI arms race
Technology is a double-edged sword. When used for good, ChatGPT has the potential to save businesses valuable time, money, and labour, thanks to its content-creation and language-processing abilities. It can also aid in learning – Singapore’s education system has chosen to embrace the technology, with appropriate guidance and frameworks, rather than crack down on it completely.
However, when misused, this application of AI can be a weapon for criminals to unleash greater harm on the public. These chatbots, which use AI-language models to generate content, could make phishing scams harder to detect. Phishing refers to a type of online scam where criminals send emails or text messages impersonating government representatives, bank officials or the authorities, tricking people into revealing sensitive information such as usernames, passwords, or other personal data.
In the past, a phishing email or text message was fairly easily recognisable due to its poor spelling and/or grammar. Now with ChatGPT, grammatical errors can be eliminated, and awkward phrasing ironed out to make phishing messages more convincing, even in languages other than English.
With these advancements, users now bear a heavier burden of trying to accurately discern between legitimate and scam messages. Fortunately, authentication technology has advanced so they don’t have to.
Padding users’ defence with passwordless authentication
It’s clear that phishing is not going away, and technology like ChatGPT is only advancing its effectiveness. According to data from the Singapore Police Force, phishing scams were the most common type of scams in Singapore, with over 7,000 cases recorded in 2022. To overcome the threat of phishing, it’s necessary to take away the most valuable piece of information criminals are seeking in these attacks: passwords.
By eliminating passwords during the authentication process, we are removing these highly prized credentials that bad actors are looking to “phish”. Instead, technology is now available for users to authenticate themselves through simpler, yet stronger passwordless verification methods, using cryptography coupled with on-device biometrics that are readily available on most devices in very user-friendly formats. With just a touch of a finger or a quick facial scan, users can log into their accounts safely and seamlessly – without fear of unknowingly handing over their credentials to scammers or through spoofed websites.
With any new technology, governance and ethical frameworks need to be established to clearly outline the boundaries of what are and aren’t acceptable uses of such tools. ChatGPT claims to have safeguarding features built into its programming to prevent bad actors from misusing the platform. But cybersecurity experts, such as those from Check Point, have demonstrated their success in circumventing these guardrails in instructing the AI chatbot to draft a conceivable phishing email.
ChatGPT is just the latest technology advancement to be leveraged as a tool to help cybercriminals be more effective at capturing personal data and sign-in credentials. Our takeaway should not be to stop advancing, but to understand that cybercriminals will always evolve and phishing will always be a threat. Our priority should not be to limit the use of such tools, but to combat phishing by providing individuals with less data to give away, starting with passwords.
The writer is executive director of FIDO Alliance.
TRENDING NOW
Grab CEO’s wife Chloe Tong on life with Anthony Tan and finding her purpose
He built the Vingroup empire. Now South-east Asia’s richest man is handing some key roles to his sons
HDB reviewing ‘jumbo’ flat scheme after Telok Blangah unit listed for sale at S$2.18m
What role can Japan play in Asean’s future?