You are the weakest link

Social engineering cracks even the tightest security, says reformed hacker

Iain Thomson

A company can have the best security infrastructure in the world and hackers will still find it easy to break thorough using social engineering, according to reformed hacker Kevin Mitnick.

He said that hackers can gain access to seemingly secure systems by using people to circumvent technology.

Advertisement

"Human resources are the weakest link in any security chain," Mitnick told vnunet.com.

"There are very basic psychological techniques you can use to get round even the most sophisticated security set-up. In some cases you can get people to offer information without being asked."

His book, entitled The Art of Deception, is loosely based on his own experiences and advises security chiefs on how to deal with social engineering attacks.

These vary from a direct request for a password by someone impersonating a member of a company's IT support team, to more cunning double bluffs and the use of guilt or intimidation.

The trick lies in collecting several pieces of innocuous information from a variety of sources until the hacker can make a final call and get the information needed to break the system.

Mitnick advises that staff should be trained to always authenticate the person asking for information, even if it means an extra phone call.

They should be encouraged to stand their ground and believe that security is more important than bowing to the requests of the apparently powerful.

Many of the highest security set-ups are the most vulnerable to this kind of attack.

The increased sense of security makes users blasé and more likely to assume that, if someone has detailed knowledge of the system, they are entitled to access.

Hackers will be disappointed at the lack of technical information in the book, but Mitnick has included two chapters for security managers which detail specific policies that can foil the social engineer.

Mitnick has also set up a specialist consultancy called Defensive Thinking which offers advice on security awareness.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Two-thirds of staff write down passwords

Can you encrypt a PostIt Note?

Mitnick takes novel approach to hacking

Truth stranger than fiction?

Bug Watch: The threat of social engineering

It ain't what you do, it's the way that you do it

Mitnick joins the Feds

Ex-hacker goes straight - into an acting role

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

IT white papers

Search white papers

Top categories

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

Piracy, privacy and processing power set to be hot topics for V3.co.uk Summit

Have you got a burning desire to quiz experts from...

iPhone

World's first iPhone virus surfaces

Images of 80s icon Rick Astley spell trouble

Airvana HubBub

Airvana debuts 3G femtocell for offices

HubBub improves indoor network coverage for businesses

shopping key

E-commerce on brink of SaaS revolution

Figleaves founder argues platform-as-a-service vendor will emerge to shake up...

Primary Navigation