Abdolmadjid Masoomi
← All topics

identity

28 pieces

  • A Family Safe Word Against AI Voice Scams: Designing One That Holds

    Most safe words fail because they are guessable, never rehearsed, or spoken on the channel the attacker controls.

    A family safe word ai scam strategy relies on shared-secret authentication, not ritual. It fails when words are guessable or never rehearsed. Designing one that holds requires unguessable phrases, challenge-response protocols, and duress variants.

    2026-09-14 · technical-essay · 9 min read

  • Account Recovery Is Your Real Password: How to Audit It

    Attackers choose the weakest way back into an account, and that is rarely the login screen.

    Most users treat account recovery security as an afterthought, leaving doors open for attackers who bypass strong login credentials entirely. A simple audit of recovery paths on your primary accounts closes these gaps before they are exploited.

    2026-09-14 · technical-essay · 8 min read

  • AI Shopping Agents: The Missing Proof You Approved the Purchase

    Card protections assume a human clicked buy; delegated agents break that assumption.

    An ai shopping agent safe requires more than trust; it demands verifiable proof of intent. Current payment systems lack the granularity to distinguish between a delegated purchase and an unauthorised action, leaving consumers to guesswork when disputes arise.

    2026-09-14 · technical-essay · 8 min read

  • Are AI Browsers Safe? The Logged-In Session Problem

    An agent that browses as you inherits every account you are signed in to.

    The question of whether are ai browsers safe depends less on the model’s intelligence and more on the permissions it inherits. When an agent operates within your authenticated session, it gains access to every email, bank account, and work tool you use daily. The practical safeguard is to isolate agent tasks in a separate profile with no standing logins to sensitive services.

    2026-09-14 · technical-essay · 9 min read

  • Charity Scams After Disasters: How to Verify Before Donate

    Fake appeals surge after crises. Learn how to verify charities and donate safely to avoid funding fraudsters.

    Scammers exploit disaster urgency via fake sites, so donors must verify charities through official registries rather than emotional appeals. This verification protects vulnerable populations and ensures aid reaches intended recipients.

    2026-09-14 · technical-essay · 9 min read

  • Deepfake Job Candidates: Remote Hiring Is Now an Identity Problem

    The interview has become an authentication step, and most hiring teams never designed it as one.

    The rise of deepfake job candidates reveals a fundamental flaw in remote hiring. Interviews now function as authentication steps that most organisations have not secured. We must treat identity assurance as a security control, not a recruiting formality.

    2026-09-14 · technical-essay · 9 min read

  • Deepfake-as-a-Service: Fraud Tools Now Come With Support

    Face swaps, voice clones and fake documents are packaged for criminals who cannot build them.

    The shift from research experiments to commercialised fraud tools marks a critical inflection point in digital security. Deepfake as a service packages sophisticated synthesis capabilities for criminals who lack technical expertise. This productisation exposes remote identity verification systems to unprecedented levels of automated attack.

    2026-09-14 · technical-essay · 8 min read

  • Digital Legacy: Planning Your Accounts and Photos After Death

    Setting up legacy contacts and password inheritance ensures your family can access or close accounts without legal gridlock.

    Digital legacy planning prevents your family from being locked out of essential accounts and memories. Proactive configuration of legacy contacts and secure password sharing is the only reliable method to manage posthumous access. Without it, legal processes often fail to resolve technical barriers.

    2026-09-14 · technical-essay · 9 min read

  • Email Aliases and Burner Numbers: Everyday Privacy Tools

    Masked emails and temporary phone numbers reduce spam and tracking, but they do not hide your identity from determined adversaries.

    Email alias privacy is a practical defence against data brokers and automated spammers, yet these tools create significant management overhead and offer no protection against targeted surveillance. Burner numbers serve similar friction purposes in verification flows but vanish when providers demand persistent identity. Understanding their limits is essential for anyone building a resilient digital life.

    2026-09-14 · technical-essay · 10 min read

  • Hacked Instagram Account? Avoid the Recovery Scammers First

    The moment you post about being hacked, you attract a second wave of fraud.

    A hacked instagram account recovery is rarely a technical puzzle; it is a social engineering trap. When you seek help publicly, scammers monitor your distress to offer fake services. True recovery requires only the platform's official channels and strict identity verification.

    2026-09-14 · technical-essay · 10 min read

  • Help Desk Social Engineering: The Password Reset Phone Call

    A convincing caller asking IT for a reset has become the easiest way past strong authentication.

    Strong authentication fails when the help desk resets it for anyone who sounds right. This analysis examines how help desk social engineering bypasses technical controls through voice manipulation and procedural gaps, outlining verification methods that do not rely on public facts.

    2026-09-14 · technical-essay · 8 min read

  • How to Know If Your Phone Is Hacked: Signs That Actually Matter

    Battery drain and heat are mostly noise; account-level evidence is where compromise shows.

    Most people chase phantom symptoms like battery drain when the real evidence sits in their accounts. You can determine how to know if your phone is hacked by checking for unfamiliar sessions and changed recovery details. This approach is far more reliable than scanning for spyware.

    2026-09-14 · technical-essay · 8 min read

  • How to Protect Elderly Parents From Scams Without Taking Over

    Controls that preserve autonomy work better than warnings and better than taking the chequebook.

    Lectures about scams fail because the scams are designed to defeat the moment of judgement, while taking control of an older parent's finances damages dignity and often gets resisted. Structural help works better: trusted-contact designations at banks, delays on new payees, a family callback rule, and a no-shame reporting agreement.

    2026-09-14 · technical-essay · 10 min read

  • How to Tell If a Voice Call Is an AI Clone (Your Ear Cannot)

    Listening harder for robotic artifacts is a losing game; the defence is moving verification off the call.

    The question of how to tell if a voice call is ai is no longer about detecting audio glitches. Modern models sound human. The only reliable defence is structural verification that does not rely on the voice channel itself.

    2026-09-14 · technical-essay · 8 min read

  • Infostealer Malware: Why a Stolen Cookie Beats a Stolen Password

    After an infostealer, changing passwords is not enough; sessions must be killed everywhere.

    Infostealer malware captures active session tokens, allowing attackers to bypass passwords and two-factor authentication entirely. Changing credentials without revoking these sessions leaves accounts vulnerable. Effective recovery requires cleaning the device and signing out everywhere before updating any secrets.

    2026-09-14 · technical-essay · 9 min read

  • Initial Access Brokers: The Market Behind a Ransomware Attack

    The intrusion you suffer was often bought, and your leaked logins set the price.

    Many ransomware incidents begin with a transaction rather than a hack. Initial access brokers sell working access harvested from infostealer logs or exposed remote services. Organisations can measure part of their risk from outside by watching for their own credentials and remote-access exposure.

    2026-09-14 · technical-essay · 8 min read

  • Insider Threat in Remote Teams: Signals Without Surveillance

    Watching access and data movement works better than watching employees.

    Most insider threat programmes fail because they watch people instead of data. Screen recording erodes trust and misses the actual exfiltration. We must shift focus to access patterns and data movement to catch real risks without invasive surveillance.

    2026-09-14 · technical-essay · 9 min read

  • Kids' Gaming Account Scams: Free Currency, Stolen Skins, Lost Accounts

    A child's game account holds items that sell for real money, which is why it is hunted like a bank login.

    Kids gaming account scams thrive because virtual items hold real monetary value. Treat these accounts as financial assets. Secure them with two-factor authentication and strict recovery controls.

    2026-09-14 · technical-essay · 8 min read

  • Non-Human Identities: The Credentials Nobody Owns

    Service accounts, API keys and tokens outnumber people, and most have no owner or expiry.

    Most organisations treat machine credentials as disposable, yet they persist long after their purpose fades. Non-human identities lack the natural offboarding cycle of human employees, creating a silent accumulation of access. The solution is not more tools, but strict ownership and expiry rules for every credential.

    2026-09-14 · technical-essay · 8 min read

  • Phishing Kits That Bypass MFA: A Subscription Business

    Adversary-in-the-middle phishing is sold with dashboards, updates and support.

    Adversaries now rent proxy kits that capture full sessions after MFA login, collapsing the skill barrier for bypassing authentication. This shift from one-off exploits to a subscription service demands a fundamental change in how we design identity systems.

    2026-09-14 · technical-essay · 8 min read

  • Phone Stolen? The First 30 Minutes, in Order

    Thieves who watched your passcode are after your accounts, not the handset.

    When your phone is stolen, the hardware is secondary to the digital identity it holds. Understanding phone stolen what to do requires prioritising account recovery over device tracking. Thieves with your passcode can bypass local locks to access cloud backups and reset passwords.

    2026-09-14 · technical-essay · 8 min read

  • Rental Scams: Fake Listings, Absent Landlords and Lost Deposits

    The fake listing is a copy of a real one; what gives it away is who controls the keys and how they want paying.

    A rental scam fake listing succeeds because it mirrors reality with genuine photos and addresses. Checking if the property exists proves nothing. The critical test is whether the person demanding payment can prove control of the keys before any money moves.

    2026-09-14 · technical-essay · 7 min read

  • Setting Up a Child's First Phone: Contact Controls Before Content

    The biggest risk on a first phone is who can reach the child, not what they might see.

    Most parents focus on content filters for their child's first phone safety settings, yet the fastest escalation of harm comes through contact. Configuring who can message, call, and add the child matters more than any filter list. Prioritising communication limits reduces exposure to grooming and scams before they begin.

    2026-09-14 · technical-essay · 8 min read

  • Should You Freeze Your Credit? Why a Freeze Beats Monitoring

    Monitoring tells you after the fraud; a freeze stops most of it before it starts, for free.

    If you are asking should i freeze my credit, the answer is yes. Monitoring only alerts you after damage is done. A freeze prevents new account fraud at no cost, offering a stronger defence than passive alerts or paid locks.

    2026-09-14 · technical-essay · 10 min read

  • Smart Glasses and Facial Recognition: Privacy for the People in View

    Consent designs built around the wearer ignore everyone the camera looks at.

    Smart glasses privacy is compromised by a design that places consent solely with the wearer, leaving bystanders with no agency. When recording merges with identification, ambient capture becomes targeted surveillance, demanding regulatory focus on capability rather than etiquette.

    2026-09-14 · technical-essay · 10 min read

  • What Your Stolen Identity Sells For, and Why It Is So Cheap

    Low prices for stolen records reflect oversupply, not low harm.

    The question of how much is stolen data worth often leads to a false sense of security. Low market prices mask the severe risk of identity reconstruction. Understanding the mechanics of value reveals why individual records are cheap but dangerous.

    2026-09-14 · technical-essay · 8 min read

  • When AI Agents Talk to Each Other, Who Is in Charge?

    Delegation chains can launder a stranger's instruction into something that looks authorised.

    In multi-agent ai security, the core risk is not just failure, but the silent laundering of authority. When agents delegate tasks without carrying the original intent, a stranger's command can masquerade as a trusted directive, bypassing the safeguards designed to protect privileged actions.

    2026-09-14 · technical-essay · 9 min read

  • Zero Trust Explained Without the Vendor Pitch

    Zero trust is a set of per-request decisions, and one stolen laptop tests whether you have it.

    Many ask what is zero trust, expecting a product to buy. It is actually a discipline of per-request verification. This essay explains the architecture without the vendor pitch, focusing on practical defence mechanisms.

    2026-09-14 · technical-essay · 8 min read