Security Confidential S15 E5 Aaron Painter

This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon talks to Security Confidential Alum Aaron Painter. Aaron is an Entrepreneur, Author, former VP of Microsoft in China, and is currently the CEO of Nametag Inc, the company who invented “Sign in with ID” as a more secure alternative to passwords.

00:00 Intro

00:57 Our Guest

01:46 Social Engineering trends

04:03 Deep fakes: how does it work?

09:18 Watermarking content

11:30 Deepfake Prevention: Injection attack

13:11: Deepfake prevention: Presentation attack

15:00 How do you verify behind a screen?

27:16 Hidden security in your phones

32:08 Social Engineering and MFA in Healthcare

41:18 How to maintain LOYAL Employees

46:15 China: Friend or Foe?

50:13 Connecting with Aaron

Transcript

Manoj Tandon (00:03.613)
Everyone, this is your host, Manoj Tandon. Welcome to another episode of Dark Rhiino Security, Security Confidential. And today we are glad to welcome back another alum who’s appeared on our show before, Mr. Aaron Painter. And for those of you who don’t remember, we’ll put a link into the prior episode. Please go check it out. He’s a great guy. He’s the CEO of Name Tag Inc. He’s been in the cybersecurity business forever. He was an executive at Microsoft in a prior life, he’s an author, he wrote the book Loyal. And we’re just glad that he’s here and we want to hear his thoughts and ideas on trends that are coming up. So stay tuned for this conversation.

And as I might want to remind you folks, this is a lot of work and we appreciate you folks listening, but we always love a little bit of love—smash and like the subscribe button, leave your comments below, we’ll be sure to answer them.

Aaron, welcome to the show.

Aaron Painter (01:04.215)
Thanks, Manoj. It’s really great to be back. I had so much fun. We had our holiday episode just in late December. So it’s really an honor to be here.

Manoj Tandon (01:11.549)
It’s an honor to have you back. And boy, since December—that was six months ago—what’s changed? In your world, in high tech, six months might as well be six years.

Aaron Painter (01:26.816)
Yeah, I think that’s fair. Lots has happened in the world and particularly in cyber. Trends that we saw at the end of last year have unfortunately only accelerated for the worse. Particularly around vulnerabilities related to social engineering. Bad actors are exploiting vulnerabilities in humans and how we do things. When they find technological limitations, they socially engineer their way into taking over accounts. And now with deepfakes and GenAI tools, they’re equipped with an unprecedented new level of technology to wreak havoc—take over accounts, deploy ransomware, and exfiltrate data.

Manoj Tandon (02:16.347)
It leads to all kinds of stuff. We’re actually in an incident response right now with someone who willingly sent money because of social engineering—mimicking credibility and asking for cash. Deepfakes weren’t involved, but you could call it a “human fake.” And you’re right—exploiting processes is something every company should take seriously.

But now deepfakes—where does that take us?

Aaron Painter (03:35.054)
Let’s define a deepfake. The term came from Reddit around 2017–2018, originally referring to synthetic celebrity images. It has evolved rapidly. GenAI tools have made voice and video manipulation incredibly easy. It’s now almost as easy as making a home video.

Researchers at Microsoft showed that with just a three-second audio clip, you can recreate someone’s voice. The more data you have, the better it gets. We’ve entered a completely new era of impersonation.

Manoj Tandon (05:06.429)
There was a Hong Kong case where a banker gave up $25 million based on a deepfake Zoom call. But from a technical standpoint—this used to require massive compute and effort. Are you saying that’s no longer the case?

Aaron Painter (06:23.532)
Exactly. The pace of change is unprecedented. Cloud computing enables large-scale data processing, which powers GenAI. And not all attacks need high fidelity. Even a blurry video can cause reputational damage. Attackers don’t always need perfection—just plausibility.

Manoj Tandon (07:57.279)
Right. If it’s on a phone, quality doesn’t even matter that much.

Aaron Painter (08:08.118)
Exactly. And now companies are trying things like watermarking—marking content as authentic. But bad actors can simply use tools without watermarking. It’s not a reliable defense.

Manoj Tandon (09:49.982)
And eventually they’ll defeat watermarking anyway.

Aaron Painter (10:07.63)
Right. That’s why detection alone is a losing game. It’s an arms race. We need prevention.

There are two main attack types:

  • Injection attacks: inserting fake video/audio feeds (like the Hong Kong case)
  • Presentation attacks: showing fake images, masks, or videos to impersonate someone

Most attacks today are injection-based because they’re easy.

Manoj Tandon (13:08.389)
APIs are wide open—it’s easy to exploit.

Aaron Painter (13:15.854)
Exactly. And that’s why identity verification becomes critical. We need to know who is behind the screen.

Manoj Tandon (14:14.619)
That’s the core issue—identity verification.

Aaron Painter (14:22.808)
That’s what led us to build NameTag. We focus on verifying both that someone is human and which human they are.

We use mobile devices instead of web browsers. Mobile apps are secure environments—Apple’s ecosystem ensures code integrity and encrypted hardware connections. That makes injection attacks much harder.

We use device cameras, sensors, and biometric matching—like 3D face mapping—to verify identity in real time.

Manoj Tandon (17:40.094)
What about people whose appearance changes?

Aaron Painter (17:50.7)
Biometric systems rely on bone structure, which remains consistent. Even with aging or weight loss, we can still match identities with high confidence.

Manoj Tandon (18:46.289)
Interesting. I’ve heard heat mapping is even more accurate.

Aaron Painter (19:37.484)
There are many advanced methods. Mobile devices already contain powerful sensors we can leverage securely.

Manoj Tandon (20:28.953)
Have you tested against high-end masks?

Aaron Painter (20:36.012)
Yes. We combine multiple data sources to detect fraud—even advanced attempts.

Manoj Tandon (22:27.037)
What about cheaper devices globally?

Aaron Painter (23:03.958)
We work across Android and iOS, but require secure environments like the Play Store or Apple App Store. India is especially advanced due to Aadhaar digital identity systems, which we integrate with.

Manoj Tandon (24:49.253)
Let’s talk policy—shouldn’t governments rethink identity systems?

Aaron Painter (25:54.242)
Some solutions exist, but adoption is the challenge. Systems like Social Security aren’t designed for modern threats. We need better identity verification infrastructure.

Manoj Tandon (29:15.054)
MFA isn’t enough—I can think of ways to bypass it.

Aaron Painter (30:35.31)
Exactly. MFA is only as strong as the reset process. If attackers can socially engineer a reset, MFA fails.

Healthcare is a major target right now—government agencies are warning about this surge.

Manoj Tandon (33:42.991)
So what are you doing to balance security and usability?

Aaron Painter (33:45.966)
Our identity verification takes about 23 seconds initially and seconds afterward. We aim for high security with low friction.

Manoj Tandon (40:07.729)
Let’s switch gears—your book Loyal. What’s the core idea?

Aaron Painter (40:11.598)
It’s about listening. Loyal stands for “Listen or You Always Lose.” Companies that truly listen to employees create loyalty, which leads to better customer relationships.

Manoj Tandon (42:45.775)
How do companies actually do that?

Aaron Painter (42:57.678)
Warby Parker is a great example. They made employees feel heard. Managers were trained to value input, and employees were encouraged to share ideas. That created trust and engagement.

Manoj Tandon (43:50.493)
Was that culture at Microsoft?

Aaron Painter (43:54.892)
Not universally, but I learned a lot there. Writing the book helped me reflect on those experiences.

Manoj Tandon (44:43.239)
Final question—China: friend or foe in tech?

Aaron Painter (44:57.228)
It’s about people, not just countries. There’s a lot of innovation there. But geopolitical separation makes collaboration harder, which ultimately hurts global progress.

Manoj Tandon (48:34.789)
That’s fascinating. Learned something new today.

Aaron Painter (48:51.062)
Final thought: social engineering is a universal threat. Be skeptical. Verify identity. If something feels off, change the channel—call directly, confirm through another method.

In a digital world, authenticity matters most.

Manoj Tandon (50:17.838)
Well said. Thanks again, Aaron.

Aaron Painter (50:41.314)
Thanks for having me. Big fan of the show.

Manoj Tandon (50:45.082)
Thank you so much, Aaron. Take care and enjoy the summer.

Aaron’s Linkedin

Learn more about NameTag Ai

Kiteworks enables organizations to effectively manage risk in every send, share, receive, and save of sensitive content. To this end, they have created a platform that delivers content governance, compliance, and protection to customers. The platform unifies, tracks, controls, and secures sensitive content moving within, into, and out of their organization, significantly improving risk management while ensuring regulatory compliance on all sensitive content communications.

Check out the other episodes in Season 15:

Ep.0 Robert Kerbeck – Fame, Fortune, and Corporate Espionage

Ep. 1 Stephen Kowski – Inside the mind of a Field CTO

Ep. 2 Vivek Ramachandran – Inside Email Security: Breaking Through Gmail and Outlook’s Defenses

Ep. 3 Dr. Eric Daimler – AI’s Future: More Than Just Machine Learning

Ep. 4 Purandar Das – Data is the New Oil

Ep. 5 Aaron Painter – Understanding Deepfakes

Ep. 6 Jake Moshenko – Navigating Open Source and Distributed Systems

Ep. 7 Nick Espinosa – Why CISOs Must Master Nerd to English Translation

Ep. 8 Dan Lohrmann – AI, Fraud, and the Future of Cybersecurity

Ep. 9 Greg Schaffer – How the Role of a vCISO is changing

Ep. 10 Sanjay Chopra – AI Innovations and the Future of Automation

podcast promo for Aaron painter, CEO of NameTage inc, on Dark Rhiino Security's Security Confidential podcast. Dark rhino security

Aaron is an Entrepreneur, Author, former VP of Microsoft in China, and is currently the CEO of Nametag Inc, the company who invented “Sign in with ID” as a more secure alternative to passwords.

Aaron has successfully integrated his human identity platform with major organizations such as Reddit and Web.com.

In his 2017 best-selling book, LOYAL, he describes his key to leadership: fostering a culture of listening.

Through codifying and implementing a business framework of listening, Aaron has built success across the world.

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top