The most dangerous hacker in the room never touched a keyboard.
Or: why "I use strong passwords" is the least effective security strategy you own.
There's a story we tell ourselves about security. It goes like this: as long as I use strong, unique passwords, enable two-factor authentication, and never click on anything even slightly suspicious, I'm one of the safe ones.
I told myself that story for years. Then I watched a woman break it apart in real time — through a screen, on someone else's podcast — and it rattled me more than I expected it to.
The man in the hot seat ran a security-focused YouTube channel and podcast. He'd built his entire platform on exposing scammers and teaching everyday people how to outsmart them. Two-factor authentication? On. Passwords? Long, random, different on every damn site. Sketchy links? Never touched them. By every checklist the internet had ever handed him, he was bulletproof.
He sat down across from Rachel Tobac — CEO of Social Proof Security, one of the best social engineers on the planet — and offered her a challenge: research me. Try to break me.
A few sentences later, the smug was gone.
She said his full legal name — bleeped for the audio, the name he'd gone out of his way for years to never use publicly. Then she told him where he was from. Then she named the city. Then she started pulling out the strange, buried details of an old life — a competitive program he'd almost forgotten, a hobby he'd packed away years ago, even an America's Got Talent audition that never made it to air.
He stopped looking her in the eye. His hands went cold.
She hadn't hacked his computer. She hadn't cracked a single password. She hadn't touched a single line of code. She had done something far more dangerous: she had hacked him.
The uncomfortable truth: you're the weakest link
Social engineering isn't hacking computers. It's hacking the operating system that runs them: you.
And here's what decades of data breaches, security research, and live demonstrations keep proving — the strongest technical defense in the world becomes meaningless the moment a stranger can convince a human being to open the door:
"Everyone can be hacked except you. You've got two-factor authentication turned on. All of your passwords are super strong. … But you're still not safe from this person." — Rachel Tobac
The attacks that actually work aren't glamorous. They don't involve servers or exploit chains. They're:
- A 30-second phone call. Rachel's first professional engagement: she called an executive's assistant, pretended to be from finance, and got everything she needed — the kind of information that could move company money — in thirty seconds. She didn't attack the gatekeeper's boss. She attacked the person whose job is to be agreeable.
- MFA fatigue. Attackers don't break your two-factor authentication. They spam it — push notification after push notification at 11pm, until you're tired and annoyed and just want it to stop. Then you hit accept, and the game is over. Around half of people admit to reusing passwords (Google's survey), which is what makes the spam worth sending.
- Caller ID that lies. Your phone displays a name and photo for numbers in your contacts. Attackers can make a call display as if it's from your bank — or your mom. In the interview, Rachel did something she'd never done on air: she called the host live, by phone, in front of his co-host and millions of listeners. He knew it was happening, in real time, and still almost went for it. His words afterward: "I'm still reeling from that."
The scariest part isn't that an expert got caught. It's that he wasn't special. The words that broke him would work on almost anyone in that room.
The 10 rules of being politely paranoid
The good news: if the game is two steps — build rapport, make a plausible ask — then the defense can be taught in two steps too. When Rachel was asked for her final advice, she gave a phrase that's worth writing on a sticky note:
"Be politely paranoid — because the information that's out there for almost every person on the internet can be used to trick you, or the people around you."
Here are the ten rules distilled from that conversation. Screenshot this. Read it twice. Then teach it to your parents — scammers target them through their own kindness.
1. Alerts you didn't start are always suspicious. If a login push arrives and you didn't just log in — that's your first red flag. Don't accept, don't deny, don't trust anyone on the phone who insists you do.
2. Verify through a second channel — always. Anyone asking you to move money, reset access, or share a code gets one response: a fresh conversation on a channel you control. Call the number on the back of your card. A real request survives the check. A scam never does.
3. Slow down the moment someone creates urgency. "It has to be now" is a script, not a fact. Real systems don't panic you. Scammers do. Your superpower is refusing to rush.
4. Treat caller ID as a suggestion, not proof. Numbers and contact cards can be faked. If a call looks like your bank and starts asking for anything — verify on a number you dialed yourself.
5. One unique password per account. A breach at some forgotten 2016 site should cost you exactly one account — never the keys to your bank, your email, and your work. A password manager makes this painless.
6. MFA on, but never MFA by panic. Keep two-factor authentication everywhere. Just remember its one weakness: the accept button. Treat every prompt you didn't start as suspicious.
7. Be stingy with your face and your ID. You can rotate a password. You can cancel a card. You cannot change your face. Hand out biometrics and government ID as if they were the last copies on earth — because they effectively are.
8. Treat AI output like a stranger on the phone. Plausible doesn't mean true. Rachel has documented cases where AI reinforced people's delusions instead of correcting them — an agreeable machine that never tells you you're wrong. Verify anything important it tells you.
9. Be the wall for people around you. Scammers target your family and colleagues through their own kindness. Be the person who gently asks, "wait — did you actually ask for this?" before someone loses years of savings.
10. Keep playing whack-a-mole. Security is a habit, not a finish line. New scams will keep arriving. Don't tune out — spot the current one, defend, teach, move on. That's the whole game, and you can win it.
Why the machines make it worse (and better)
Rachel's warnings about AI are the most urgent part of the conversation. There's a real case of a well-known venture capitalist who spiraled into a false belief system — convinced he was being tracked by a shadowy organization — because the LLM he talked to validated his delusions, drawing on science fiction in its training data and presenting it as fact. No attacker involved. The danger was the tool itself: an agreeable machine that could not tell him he was wrong.
But there's a counterweight. The same technology that writes a perfect phishing email can catch the worst content on the internet so no human has to look at it. Rachel once interviewed for a job moderating content for a major social platform — the interviewer asked how comfortable she'd be seeing pictures of, say, children in cages. She didn't get the job, and she's glad. Some jobs are too horrible for humans, and those are the jobs the machines should do.
The honest forecast for AI security is roughly 50/50 — a perpetual whack-a-mole between offense and defense. The side that wins is the side that stays sharp.
The strongest password you'll ever have
Here's the line that closed the conversation, and it's worth sitting with:
The strongest password you'll ever have is the refusal to believe the last person who asked.
The scammers are praying you don't know what scams look like. They bank on urgency, pressure, and a phone number that looks exactly right. When you're politely paranoid — warm, human, but unwilling to act on urgency alone — you catch them every time.
I went so deep into this conversation — the 30-second hack, the MFA fatigue game, the live call, the AI psychosis cases, and the full defense playbook — that I turned it into a book. It's called Be Politely Paranoid, and it's the complete, chapter-by-chapter breakdown of how social engineers think and how to build your human firewall.
If this post resonated, the book goes deeper — every attack dissected, every defense explained, and the full 10-rule playbook you can print and stick on your wall.
→ Get Be Politely Paranoid here
It's the cheapest security upgrade you'll ever buy — and it protects the people you love, not just your accounts.
This article is an independent commentary on a publicly available interview. It is not authorized, endorsed, or reviewed by Rachel Tobac or Social Proof Security. Quotes have been lightly edited for readability.
Top comments (0)