Modern Wisdom
Modern Wisdom

What Is An Ethical Hacker? - Thomas Johnson - #105

Thomas Johnson is an ethical hacker and social engineer. Hacking is often thought of as a dark art. Dark basements and illegal activities. But there's an entire other world of hackers who are using their skills to subvert security systems both online and offline for good. Expect to learn just h

Featured Speakers

Chris Williamson Host

Episode Summary

Executive Summary: The conversation explores ethical hacking and social engineering through Tom Johnson’s origin story, tools, and real-world demonstrations. It contrasts white-hat security work with criminal hacking, showing how human behavior, not just software, is the key weakness. The episode emphasizes data as a strategic asset, the rise of information warfare, and the need for better education, awareness, and practical security habits.

Main Topics: Defining social engineering and ethical hacking (Priority: 5/5): Tom explains social engineering as using psychology to get targets to reveal or do something they shouldn’t, arguing that humans can undermine even strong technical defenses. Tom Johnson’s path into cybersecurity (Priority: 5/5): He traces his journey from a bored child on computers, to youthful hacking and college expulsions, to being scared straight by a staged police arrest, and later returning to cybersecurity as a lawful profession. Physical and covert hacking tools (Priority: 5/5): The discussion covers devices such as USB Rubber Ducky, Bash Bunny, Raspberry Pis, covert cameras, SDRs, and keyless-car relay attacks, illustrating how hackers blend tech and deception. Corporate penetration testing and infiltration tactics (Priority: 4/5): Tom describes an ethical hack on a company, including reconnaissance on staff, cloned access cards, impersonation, and covert surveillance, to show how quickly an attacker can gain access. Password security and data breaches (Priority: 5/5): They discuss common password habits, brute force and dictionary attacks, password managers, and the risks of password reuse after breaches like LinkedIn leading to account compromise. Nation-state cyberwarfare and strategic risk (Priority: 5/5): The episode broadens into state-level threats, Stuxnet, election interference, and the claim that data is now more valuable than oil, making information warfare a core future battleground. Career advice and learning pathways (Priority: 3/5): Tom recommends platforms like Hack The Box, OverTheWire, and Mercer Labs for safe practice, and argues cybersecurity offers strong pay and high demand for skilled professionals.

Key Arguments: Humans are often the weakest link in security, because a convincing lie or social pretext can bypass expensive technical controls. Social engineering works because people trust appearances, authority, and social association more than they should. White-hat hacking uses the same tools as criminals, but with lawful scope and defensive intent. Reputation and pretexting matter: people are more likely to comply when they see a hacker associated with someone they recognize. Password reuse is dangerous because a breach on one platform can cascade into many others through credential-stuffing and recovery flows. Strong security requires both technical controls and user education; awareness training is as important as software. Nation-states and criminal groups treat cyber capability as a force multiplier, making information warfare a major part of modern conflict. Data collection and public online behavior create a growing attack surface for both criminals and state actors.

Data Points: Age started hacking: About 12 years old - Tom says his interest began when he was a child given access to a computer. Age of first police incident: About 16–17 - He describes the staged arrest/scare tactic as happening in his teens. Certification in progress: OSCP (Offensive Security Certified Professional) - Tom says he is studying for it and expects to receive it in about two months. Exfiltration timeline: 15 minutes - In the company penetration test, he says he gained internal access within 15 minutes of exploitation. Reconnaissance period: About 3 weeks - He spent three weeks gathering intelligence on staff before the company engagement. Staff targets prioritized: 5 staff members - He selected five employees he believed were weakest links for social engineering. Conference audience size: 600 - He speaks about presenting at an invite-only cyber security conference to around 600 professionals. USB Rubber Ducky typing speed: Thousands of characters per minute - Described as a device that emulates a keyboard and can rapidly type payloads. Car theft technique window: Under 30 seconds - The host references reports of keyless car theft using relay attacks in less than 30 seconds. Password cracking time: 2 hours - He claims the full eight-character character set can be cracked in about two hours with modern GPU cracking. Average penetration tester salary: £65,000–£120,000 per year - Tom cites this range when discussing cybersecurity careers. Job deficit: £1.8 million job deficit within three years - He claims there will be a major shortage of qualified cyber professionals. SDR frequency range: 1 megahertz to 6 gigahertz - He gives the operating range of the software-defined radio transceiver. Zero-days in Stuxnet: 4 - He says Stuxnet contained four zero-day vulnerabilities, indicating nation-state sophistication. Attack duration for data collection: 30 days - He explains Stuxnet recorded factory stats covertly for about 30 days before sabotage.

Pivotal Quotes: "data now is worth more than oil" — Tom Johnson: Used to frame why cyber defense and information warfare are now strategic priorities. "Humans can be the weakest link, but they can also be the strongest link as well" — Tom Johnson: He explains that people can either enable attacks or serve as the best defense through awareness and intuition. "for the price of one fighter plane, you can hire 200 hackers" — Tom Johnson: He argues cyber capability offers high strategic value compared with traditional military assets.

Implications: Listeners should treat cybersecurity as a human problem as much as a technical one. The episode suggests stronger passwords, unique logins, device caution, and awareness training are essential as cybercrime, surveillance, and state-sponsored attacks grow more sophisticated.

🔓 Sign Up for Unlimited Episode Search

About Modern Wisdom

Chris Williamson in long-form conversation with the world's most interesting people - psychologists, scientists, authors, comedians and entrepreneurs - on life, science, health, fitness, business and philosophy.

View all episodes from Modern Wisdom