
Evan Tobac
@evantobac
Security Researcher, Maker | Co-Founder, Head of Research & Tech at @SocialProofSec | @BSidesSF Review Committee | He/him | infosec.exchange/@evantobac
ID: 949172506052608000
http://SocialProofSecurity.com 05-01-2018 06:55:35
166 Tweet
1,1K Followers
806 Following

Great overview of the dangers of password reuse due to data breaches by Rachel Tobac, Evan Tobac * Find email addresses via OSINT * Password breach databases ➡️ plaintext passwords, hashes, and hints * Customized wordlist + ruleset ➡️ hashcat Be safe: Password manager, MFA




Here’s how I used AI to clone a 60 Minutes correspondent’s voice to trick a colleague into handing over her passport number. I cloned Sharyn’s voice then manipulated the caller ID to show Sharyn’s name with a spoofing tool. The hack took 5 minutes total for me to steal the info.

*Sizzle Reel + Ransomware Song Debut!* We just hit 500,000+ users for our SocialProof Security security awareness training video library 🤯🤘 To celebrate, here's a sizzle reel of our latest Spoken and Music Video content with the DEBUT of our Ransomware Song in the background --

Our DEF CON Clue Hunt is starting soon & it’s bigger than ever before! 1st clue & Keymasters at Social Engineering Community starting Fri. Teaser of prizes — challenge coin completes a circuit on our badge, lighting it up. Rachel Tobac @EvanTobac are so excited to see all the Clue Hunt winners!






I just live hacked Arlene Dickinson (Dragons' Den star - Canada's Shark Tank) by using her breached passwords, social media posts, an AI voice clone, & *just 1 picture* for a deepfake live video call. Thank you Elevate Mastercard for asking me to demo these attacks live!