episode.ascii — live render
● episode

Episode 1: Email Spoofing

TL;DRIn 2013, a spoofed press release falsely announced Samsung had acquired Swedish firm Fingerprint Cards, briefly roiling its stock market. The episode explains how email spoofing works — no password needed — using a live demo.

Hey new listener! This original pilot episode is pretty vintage. If you're just getting into hacked, we recommend starting anywhere in the 2020 reboot. Cheers!

In this episode, we explore a technique known as "e-mail spoofing".

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: In October 2013, a bunch of tech journalists got a press release from a Swedish biometric company called Fingerprint Cards. The press release was announcing the fingerprint sensor manufacturer had been bought out by none other than Samsung, which is pretty big news, not just for the company, but for their shareholders. Media covered the press release, and for seventeen minutes, the Swedish stock market went kinda nuts with the news before the stock was frozen due to volatility. Samsung had bought Fingerprint, and a lot of people stood to make a lot of money off of the deal. The only problem is Samsung didn't actually buy Fingerprint. And that press release from a Fingerprint PR person that started the whole thing? Fingerprint didn't actually send it. I'm Jordan Blumen.

Speaker 2: And I'm Scott Winder.

Speaker 1: And this is Hacked, a podcast about the curious, enlightening, and occasionally criminal underbelly of the Internet. Can we, can we cut the suspenseful jams? Perfect. Thanks. Starting something new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you You can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked. Okay. So who who are we? As I said earlier, my name is Jordan.

Speaker 2: And I'm Scott.

Speaker 1: Scott has twenty years experience in tech with an extensive computer security background.

Speaker 2: And Jordan? Well, he spent his career in communications, and he's got something that we refer to as a penchant for storytelling.

Speaker 1: Thanks, Scott. We decided to make this podcast because fifteen years ago, digital security was a pretty obscure subculture. Today, it's kind of at the heart of political, personal, and pop culture.

Speaker 2: Every day we're exposed to cybercrime because, you know, every day our lives move more and more online.

Speaker 1: So we figured we would talk about it and try and understand it so we can be both more aware and less afraid. So where do we start?

Speaker 2: Today, we're gonna talk about email spoofing.

Speaker 1: This is normally where we would play the theme song, but this week, we're saving that for the end. It's kinda shameless, but stick around.

Speaker 2: Email spoofing is the practice of sending out an email masquerading as someone else. You need to log in to your email account to read the emails that people have sent to you, but you don't need to log in in order to send an email from your email address or someone else's. Hence, spoofing. You're faking or spoofing who the email is actually coming from.

Speaker 1: When I sit down in front of my computer, I log in to Facebook. I type in my username and I type in my password, at least if my browser didn't remember it for me. In the same way, if I sit down on my computer and I wanna log in to my email, I type in my email and I type in my password. From my perspective, these two things are very, very similar. But to someone trying to pretend to be me on the Internet, they couldn't be more different.

Speaker 2: Email is an ancient service. It's as old as the Internet itself, and it was created to be kind of this anarchistic, egalitarian distributed network. It really requires no login or authentication to provide any kind of proof of who you are sending and who you are sending it to.

Speaker 1: Communication on the Internet really just boils down to trust. If I see a message from someone I know, of course, I'm gonna open it. I trust that person. If I see a message from someone who I don't know, it becomes a question of discretion. If it's from some weird Russian website trying to sell me Viagra or Cialis, I'm probably not gonna open it. If it's someone I met a little while ago, yeah, maybe I'll open that email. And knowing that that's how people decide what they do or don't open is a pretty valuable tool.

Speaker 2: Being able to, you know, kind of jump into somebody else's trust network and use a preexisting trust relationship can be incredibly powerful. You know, if like as Jordan said, you get, like, a sketchy Russian Cialis salesman sending you attachments, chances are you're not gonna open them. But if your grandma sends you an invite to their her ninetieth birthday party or something along those lines, there's a good chance that you're gonna open it.

Speaker 1: I love you, nana.

Speaker 2: And that's just it. You know, the base starts there. You know, there's a variety of reasons that people can do this and would do this, you know, bypassing people's security, stealing personal information, installing, you know, software that allows them to take over your computer, or things like stock manipulation, which is how we open the show, are totally viable. Like, just today, I made Jordan quit his job without him knowing.

Speaker 1: Wait. What? Hello? Hey, man. It's Jordan. How are you doing? I'm alright. How are you? I'm not too bad. Did you just get an email from me? I did. What's it say? I'm quitting. Okay. So I didn't send that email.

Speaker 2: No. I did.

Speaker 3: You did?

Speaker 1: Yep. Okay. So how did you send that email? You did you have my password?

Speaker 2: Not at all. So all I did was draft up what I wanted the email to look like, copied it into my clipboard, connected to an email server, say that I was you, and send it to him.

Speaker 1: And how long did that take?

Speaker 2: About two minutes.

Speaker 1: Okay. So I asked Scott to take me through the process of sending an email from my account without ever logging in as me. And more than the feeling of having your privacy invaded, more than the surreal sense of, I guess, watching someone pretend to be you. What struck me most was how easy this all was. Like, like, really, really easy. Here's what he did. Scott opened up the terminal on his computer. If you picture people hacking in a movie, you know that like black screen with a bunch of sort of just ominous nonsense scrolling by, it's that thing.

Speaker 2: It but real.

Speaker 1: Right. I have my doubts. Then he wrote a line of text saying hello to the mail server. It was one line of text. So I've always assumed the computers talking to each other it was ones and zeros or at best just something completely indecipherable. What Scott wrote in the terminal was a line of text that I could actually read. It was almost plain English and the server responded in English. So if that wasn't weird enough, the next step is that he said he was me to the server and he did that by writing in my email address as the sender and he hit enter. He didn't write a password just the email and the server literally responded, okay. It just kind of trusted him. Then he wrote the recipient like you went on an email. That was the email address of the person you just heard. He wrote subject, I'm quitting, and then he composed an email. All of this in that ominous black terminal. And that was kind of just it. Scott never logged into my email. He never needed my password. He just sort of put on a Jordan mask and started walking around pretending to be me. And the Internet believed him.

Speaker 2: Yep.

Speaker 1: What the actual hell, dude?

Speaker 2: This is, this is the language of the Internet.

Speaker 4: Thinking about refreshing the carpet in your home? Now's the time to do it. For a limited time at The Home Depot, get 10% off installed carpet projects on trusted brands like Lifeproof, Lifeproof with PetProof Technology, Home Decorators Collection, and Traffic Master. Plus, with installation starting at just 49¢ per square foot, upgrading your space is more affordable than ever at The Home Depot. Offer valid 06/11/2026 through 06/28/2026. Exclusions apply for licenses, see homedepot.com/ license numbers.

Speaker 2: I'm gonna get a bit technical now and give you a bit of background of, you know, why this is possible. Jargon alert. Language of email is called SMTP or Simple Mail Transfer Protocol. This language was created to standardize digital messaging, and it was done so in 1982.

Speaker 1: If you're

Speaker 2: old enough to remember the Internet of 1982, you're old enough to know that it really wasn't publicly available. Organizations that were on the Internet had their own mail servers that would accept emails for their users and relay emails from their users to others. The key term here is relay.

Speaker 1: So what's a relay?

Speaker 2: Well, a relay is when a message is sent to a server but destined for another server. The server then just redirects it to the appropriate server. The term open relay is used to describe a server that has no restrictions on this redirection. Open relays were incredibly prevalent in the late nineties and early two thousands until the age of spam that brought these loopholes to the forefront of our full inboxes. Today, finding truly open relays is very difficult. And if you do manage to find one, it is probably on a blacklist, a list of known servers used by spammers and criminals and therefore is essentially useless. But open relays are quite common. The company that provides your home internet probably also provides you with an SMTP server to use. They do this so that they can firewall off your access to external SMTP servers while still allowing their subscribers to send emails.

Speaker 1: So the point of all that, what you're saying is that anyone with an Internet connection still has access to one of these servers, which, if I'm understanding correctly, is really all you need to spoof an email.

Speaker 2: Yep. And I should probably take the opportunity now to tell you that email spoofing is illegal.

Speaker 1: It's illegal.

Speaker 2: Very illegal.

Speaker 1: Okay. So someone can send my banker an email pretending to be me.

Speaker 2: Right. Your banker gets an email from you.

Speaker 1: From me? Right. Air quotes. But that would be the end of it because the second he responds, it just goes to my email address, which this hacker presumably doesn't have access to. Hacker's not gonna be able to get, like, my monthly statement or request any information.

Speaker 2: Not necessarily. SMTP provides a way for the sender to specify a separate email address that is only used when replying to that specific email. So your banker receives an email from jordan@hackedpodcast.com, trusts that it's from you, clicks reply, and the email address the reply will be sent to can be totally different. As your banker, if you don't go out of your way to verify this new recipient, you'll never even notice. And clever people will even go out of their way to make this new malicious email look just like the original one.

Speaker 1: Look like the original one.

Speaker 2: Well, again, you know, using you as the guinea pig, jordan@hackedpodcast.com, if I were to register an email, jordan hacked quad cast dot com, replacing the p in pod to a q, the email address from a strictly visual sense are almost perfectly equivalent.

Speaker 1: And now that we've said that, anyone getting emails from Jordan at hacked quad cast dot com should probably just disregard them.

Speaker 2: But even if somebody takes the time to verify, to take a second look at it, really, they're gonna see no difference. So do you get it?

Speaker 5: In, in broad strokes, yeah.

Speaker 1: I kinda I think I do.

Speaker 2: Can you can you guess where the secret sauce is? You know, the last hurdle?

Speaker 1: Last hurdle. Well, if it's if it's this easy to send an email from my email address, the next trick would be convincing the person you're sending to that the email was actually written by me.

Speaker 2: Right.

Speaker 1: Which if I'm being honest, couldn't really be that hard. Because every single day I publish a guide to how to imitate Jordan Blumen online online. You can read how I write on Facebook. You can see what's going on in my life on Twitter. You can figure out where I am on Instagram. It really wouldn't be that hard to pretend to be me with all that information available.

Speaker 2: And you know what they say, a picture is worth a thousand words. If I see see on Instagram that you're somewhere like Niagara Falls, I download that photo and attach it to an email that I send your parents with an update from your trip. There's no way that they won't believe it's you.

Speaker 5: Well, that's why I stick

Speaker 1: to postcards. So is there any way to protect against this, or is it just don't use email?

Speaker 2: Not really. You know, the protection that we have today is way stronger than it was fifteen years ago, and that's because people like Google and Microsoft have spent tens of millions of dollars researching how to protect against it. You know, this problem dates back to 1982. So redefining the way something works and something that billions of people use

Speaker 1: It's gonna be pretty tough.

Speaker 2: Yeah. Almost impossible. Almost. Well, you can use more reputable email services. You know, there are a lot of forms of protection that do exist, but you have to trust your email provider has implemented them and is validating against them, you know, to have any kind of confidence.

Speaker 1: Right. So if people can do this and your security comes down to your email provider to catch these spoofed emails before they even get to you.

Speaker 2: Right.

Speaker 1: Right. Is every episode gonna leave me with this weird feeling?

Speaker 2: I think so. Yeah.

Speaker 1: Yeah. I think I knew the answer to that. This has been Hacked episode one. I'm Jordan Blumen.

Speaker 2: And I'm Scott Winder.

Speaker 5: And to wrap things up, we're gonna

Speaker 1: play ourselves up with the official hacked podcast theme that we promised you earlier.

Speaker 2: This episode has been produced by Sticks and Stones, art and design by Mathias Schmale. Thanks for listening.

Speaker 6: Visible puts the ultimate wireless hack in the palm of your hand. You get unlimited five gs data and hotspot designed to keep you connected. All powered by Verizon's five gs network. Plans start at $25 a month or get the premium Visible Plus Pro plan and save $10 on your first month with promo code HACK. Tap the banner to switch today. Terms apply. See visible.com for plan features and network management details.

Speaker 7: The right window treatments change everything. Your sleep, your privacy, the way every room looks and feels. At blinds.com, we've spent thirty years making it surprisingly simple to get exactly what your home needs. We've covered over 25,000,000 windows and have 50,005 star reviews to prove we deliver. Whether you DIY it or want a pro to handle everything from measure to install, we have you covered. Real design professionals, free samples, zero pressure. Right now, get up to 45% off-site wide, plus get a free professional measure at blinds.com. Rules and restrictions apply.

Speaker 3: Athletic brewing company crafts award winning non alcoholic beers for those who wanna be part of every round with over 185 flavor awards. They're exceptional NA beers that fit your lifestyle and any social occasion. Summer's full of good times and athletic fits right in. Go to athleticbrewing.com to have brews delivered to your door or find them at a bar, restaurant, or store near you. Near beer, athletic brewing company fit for all times.