You are the weakest link

Social engineering cracks even the tightest security, says reformed hacker

Written by Iain Thomson

A company can have the best security infrastructure in the world and hackers will still find it easy to break thorough using social engineering, according to reformed hacker Kevin Mitnick.

He said that hackers can gain access to seemingly secure systems by using people to circumvent technology.

"Human resources are the weakest link in any security chain," Mitnick told vnunet.com.

"There are very basic psychological techniques you can use to get round even the most sophisticated security set-up. In some cases you can get people to offer information without being asked."

His book, entitled The Art of Deception, is loosely based on his own experiences and advises security chiefs on how to deal with social engineering attacks.

These vary from a direct request for a password by someone impersonating a member of a company's IT support team, to more cunning double bluffs and the use of guilt or intimidation.

The trick lies in collecting several pieces of innocuous information from a variety of sources until the hacker can make a final call and get the information needed to break the system.

Mitnick advises that staff should be trained to always authenticate the person asking for information, even if it means an extra phone call.

They should be encouraged to stand their ground and believe that security is more important than bowing to the requests of the apparently powerful.

Many of the highest security set-ups are the most vulnerable to this kind of attack.

The increased sense of security makes users blasé and more likely to assume that, if someone has detailed knowledge of the system, they are entitled to access.

Hackers will be disappointed at the lack of technical information in the book, but Mitnick has included two chapters for security managers which detail specific policies that can foil the social engineer.

Mitnick has also set up a specialist consultancy called Defensive Thinking which offers advice on security awareness.

Tags:

Further reading

Two-thirds of staff write down passwords

Can you encrypt a PostIt Note?   More...

Mitnick takes novel approach to hacking

Truth stranger than fiction?   More...

Bug Watch: The threat of social engineering

It ain't what you do, it's the way that you do it   More...

Mitnick joins the Feds

Ex-hacker goes straight - into an acting role   More...

Related articles

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

25 Jul 2008

7.85 MBPodcast Special: Views from the Valley More...

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement