this post was submitted on 28 Oct 2023
258 points (94.2% liked)

Technology

59298 readers
4481 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

IBM researchers said a ChatGPT-generated phishing email was almost as effective in fooling people compared to a man-made version.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 140 points 1 year ago (2 children)

IBM researchers said a ChatGPT-generated phishing email was almost as effective in fooling people compared to a man-made version.

So it's less effective than a regular phishing email?

[–] [email protected] 45 points 1 year ago (2 children)

Yes, but being about the same means ChatGPT could be used to create massive amounts or personalized phishing emails at a low cost in a very short time by automation. Basically doing what they do now, but even faster.

[–] [email protected] 5 points 1 year ago (2 children)

And with better spelling and punctuation.

[–] [email protected] 8 points 1 year ago (1 children)

No, those 'mistakes' are part of the phishing tactic. It weeds out those that are paying too much attention to the details.

[–] [email protected] 1 points 1 year ago

Better spelling and punctuation is a bug, not a feature.

Bad spelling = people who miss those may be easy to fool.

[–] [email protected] 1 points 1 year ago

I wonder how that would work. The last one I did some checking into had a bitcoin address and it (I really don't understand Bitcoin well) looked like the person moved the fake money from account to account over and over again.

[–] [email protected] 27 points 1 year ago (2 children)

And crafting a carefully targeted phishing email took a human team around 16 hours, they wrote, while ChatGPT took just minutes

This is significant because any person with the desire to scam can use ChatGPT from the comfort of their own home over lunch instead of hiring professionals for a few days.

[–] [email protected] 8 points 1 year ago

No, it's significant because attackers can pump out way more emails while also making them customized to their targets and constantly changing to help avoid detectors.

[–] [email protected] 3 points 1 year ago

You don’t need a professional to write a scam email. You just need common sense, to be honest.