Phishing emails, flawlessly written thanks to artificial intelligence, convincingly real profiles on social networks, and smart chatbots that extract data from us during conversations: digital spaces are becoming a security risk almost daily. How can users effectively protect themselves? Dr. Nicolás E. Díaz Ferreyra, a researcher at the Institute of Software Security at TUHH, offers tips for dealing with AI and similar technologies – and explains what technical protection has to do with self-awareness.
1. Fraud by Email: Know Your Own Vulnerabilities
Classic warning signs like spelling mistakes or poorly copied logos are often a thing of the past due to modern AI tools. Fraudulent emails are visually and linguistically hardly distinguishable from genuine messages. However, according to Díaz Ferreyra, phishing operates not only through technology but above all through psychology: “If you know which buttons are easiest to press for you, you are already much better prepared.” Under stress or time pressure, we do not rationally weigh risks; instead, our brain uses mental shortcuts – so-called cognitive heuristics. “Phishing works because attackers exploit our cognitive and motivational biases extremely well. They try to create situations in which we want to respond quickly, believe what we see, or don’t question it too closely.”
In a university environment, this might involve fake invitations to conferences or scholarly journals. Even when doubts quietly arise, according to Díaz Ferreyra, the desire for the offer to be genuine often prevails.
Practical tips for everyday life:
- Know your own trigger points: Which messages make me curious, anxious, or proud? Knowing your emotional buttons helps you see through manipulation attempts faster.
- The old rule “If it sounds too good to be true, think twice” also applies in the AI age.
- The independence check: For unusual requests such as money transfers or password entries, only an independent channel helps. Use an official phone number or type the web address manually. Never trust links in the message blindly.
2. Healthy “AI Hygiene” When Using Chatbots
Large language models and AI assistants are increasingly part of our everyday life. Often, however, we underestimate a psychological phenomenon: we tend to humanize AI systems. “Because we communicate so naturally with AI assistants,” explains Díaz Ferreyra, “they feel less like software and more like knowledgeable, trustworthy interlocutors. This makes us careless.”
This leads users to quickly share intimate details, health questions, or confidential work documents in an AI window – data they would never disclose on a normal website. But large language models can store information, and under certain conditions, strangers could later retrieve this data and use it for entirely different purposes. Díaz Ferreyra also warns against blindly trusting AI expertise. Answers often sound extremely confident and convincing, even when completely wrong. Anyone who acts uncritically afterward, especially on health or financial topics, risks their own security.
Practical tips for everyday life:
- The two-question principle for AI use:
1. What do I give the system? (Is it sensitive data?)
2. What do I take from the system? (Have I verified the facts?) - Don’t share secrets: Treat the chatbot like a public forum, not like a confidential diary or a one-on-one conversation.
- Fact-check important topics: Never trust AI responses blindly on subjects like health, finance, or legal issues.
3. Beware of Manipulative Designs
Platforms like Instagram or Facebook feel familiar and harmless. This is deliberate: warnings about fraud or data misuse are often hidden in the design. Moreover, providers use so-called “dark patterns” – manipulative design tricks on user interfaces. A typical example: the button for data protection is hidden deep in the menus, while allowing all data with a single click is easy. “The EU has taken important steps with the Digital Services Act and prohibits certain manipulative designs,” says Díaz Ferreyra. “This is important because data protection and autonomy depend not only on whether someone clicked ‘Yes’ or ‘No.’ The way this choice is presented is also crucial.”
For the future, the researcher hopes for digital warning notices, so-called “privacy nudges.” They work like nutrition labels on food: they don’t prohibit anything but clearly show risks at the moment of decision, for example, when uploading a photo or sharing location. Importantly, they should be used sparingly to avoid overwhelming users with warnings.
Practical tips for everyday life:
- Consciously slow down: If an app pressures you or demands quick clicks, pause briefly.
- Take the difficult path: Ignore the convenient “Accept all” button. Look specifically for “Decline” or “Settings,” even if it takes more clicks.
What Gives Hope for the Future
Despite many risks, Díaz Ferreyra looks to the future positively. Awareness of online dangers and the responsibility of tech companies is higher today than ever before. Governments are also increasingly taking action: Australia, for example, has introduced strict age limits for social networks. For the expert, however, the solution lies neither solely with smarter users nor better technology. Instead, he says, it requires the combined efforts of all parties: “I think the way forward requires much stronger interdisciplinary collaboration. Computer scientists cannot solve these problems alone, nor can psychologists, lawyers, policymakers, or educators. The reason why I’m optimistic is that we are increasingly recognizing this fact.”
Further publications by our expert on the topic:
- Díaz Ferreyra, N.E., Ostendorf, S., Aïmeur, E., Heisel, M. and Brand, M., 2022, September. ENAGRAM: An app to evaluate preventative nudges for Instagram. In Proceedings of the 2022 European Symposium on Usable Security (pp. 53-63).
https://dl.acm.org/doi/10.1145/3549015.3555674 - Aïmeur, E., Díaz Ferreyra, N.E. and Hage, H., 2019. Manipulation and malicious personalization: Exploring the self-disclosure biases exploited by deceptive attackers on social media. Frontiers in Artificial Intelligence, 2, p.26.
https://doi.org/10.3389/frai.2019.00026