ChatGPT’s impacts will be social, not technical

Issue 8 2022 News & Events

The technology world was on fire about the latest artificial intelligence demonstration by OpenAI in the waning months of 2022, ChatGPT. It is truly a remarkable achievement; an artificial intelligence (AI) that can converse and be asked to do everything, from writing essays, to coding of computer programs.

As a computer security expert, I immediately did what came naturally to people like me; I tried to hack it. Could I get it to do something bad, something malicious? Could this be abused by criminals or spies to enable new types of cybercrime?

The answer, of course, like most tools, is yes. Someone with ill intent can abuse these miraculous scientific achievements to do things that could likely cause harm. The surprising part, however, is that the danger lies in the social arena, not the technical one.

While ChatGPT can be tricked into writing malicious computer code; that is not very scary. Computer code can be analysed by computer security products in milliseconds and be deemed malicious or safe with a high degree of certainty. Technology can always counteract technology. The problems surface when what we are trying to detect is not computer code, but rather words and meaning that will be interpreted by humans, not machines.

Two factors make this dangerous. The first is that up until now, it was not practical to have a computer create tempting lures for tricking victims to interact. The technology is now, not only available, but also so easily accessible as to be cheap, or even free. The second is that the primary way users keep themselves safe today is by noticing mistakes made by attackers in their grammar and spelling to detect that an email or communication may be from an intruder.

If we take away the last remaining sign that someone without a strong command of the language created a malicious email or chat message carelessly, how will we defend ourselves?

In my eyes, this signals the end of most computer users’ ability to discern real mail from fake. Today these tools only work well for English language text, but that is a simple training issue. The ability to write fluently in any language in the world (including computer-programming languages) is here. We must rethink our approaches to user education and implement technical measures to prevent these messages from ever making it into their inboxes.

The good news is that computers are quite good at detecting and potentially blocking most of this content. Ultimately, a spam campaign always has some sort of call to action, they may want you to phone them, reply, click a link or open an attachment. These are impossible to remove and can aid in detection. We can also train AI models to detect when ChatGPT has generated text and add a warning banner, or perhaps block the message.

The problematic situations are when we fail to block them and they end up in someone’s inbox. It is a reasonably small percentage, but it is not zero, and therefore we must prepare a defence. Having defensive layers is essential and with humans’ having reduced ability to spot a scam it is even more important that users are connecting through firewalls and web protection that can detect and block threats.

User training will need to shift away from the ‘watch for spelling mistakes’ type of messaging, and more into risk-based approaches to verification of whom you’re talking to. If asked to do something financially, with a password, or with sensitive data, pick up the phone and confirm before proceeding.

As machine intelligence continues to advance, the work of separating fact from fiction will continue to get more and more difficult. We will need to be sure we build systems that are flexible enough to combat these messages, but also educate our staff on their need to take additional steps when receiving sensitive requests over email.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

From the Editor's desk: Security goes mainstream
Technews Publishing News & Events
      Welcome to SMART Security’s SMART Mining & Industrial Security Handbook 2026. While the world is focused on cybersecurity and AI, physical security has become a board-level concern across South Africa’s ...

Read more...
Global security in 2026
Editor's Choice News & Events Security Services & Risk Management Industrial (Industry) Mining (Industry)
The World Security Report 2026 states: “In a world of increasing volatility, physical security has evolved. It is no longer just a defensive measure; it is a critical driver of corporate value.”

Read more...
Industry perspective on industrial cybersecurity
Technews Publishing News & Events Infrastructure Industrial (Industry)
The Industrial Security Harmonization Group has released a joint industry perspective highlighting a critical truth in industrial cybersecurity: secure communication is not determined by protocols alone, but by how they are deployed and managed in real-world environments.

Read more...
Impro announces Primo update
News & Events Access Control & Identity Management Integrated Solutions
Impro Technologies recently held a launch event in which it introduced a series of new products, from new readers through to its updated Primo access management software.

Read more...
IQSight SmartSuite integration with XProtect
Surveillance News & Events AI & Data Analytics
Milestone Systems and IQSight have strengthened their collaboration with the release of SmartSuite, a consolidated plug-in suite for Milestone XProtect video management software, to cut installation time for system integrators by 70%.

Read more...
The future of smart living and connected security
Securex South Africa Smart Home Automation News & Events
From controlling access and surveillance remotely to managing energy use during blackouts, smart technologies are transforming how organisations and property owners operate, protect assets, and maintain uptime across residential and commercial environments.

Read more...
957 women killed in three months
News & Events Security Services & Risk Management
Despite years of summits, task teams and public commitments, South Africa’s femicide rate remains around five times higher than the global average, and too few are using the legal lifelines available.

Read more...
AURA appoints Taryn Winer as global head of people
News & Events Security Services & Risk Management
Following its €13,5 million Series B funding round last year and accelerating international expansion, particularly across the United States, AURA has appointed Taryn Winer as global head of people.

Read more...
Gallagher Security releases new fence controllers
Perimeter Security, Alarms & Intruder Detection News & Events
Gallagher Security has announced the release of its new F5 and F6 Fence Controllers, marking the latest generation of enhanced-safety, monitored-pulse fence technology, designed to meet the demands of modern security environments.

Read more...
Paxton set to launch game-changing new system
Paxton Access Control & Identity Management News & Events
Access control is evolving fast. Installers and end users are looking for systems that are simple to install, easy to manage remotely, and flexible enough to scale. In response, Paxton is exploring how emerging technologies can reshape access control.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.