The Art of Deception

The Art of Deception: Controlling the Human Element of Security: Mitnick
(See online!)

When I taught Operations Security to the military, contractors, at the Pentagon, and more, I told the story of Kevin Mitnick. The world's first hacker to hit the FBI's most wanted list. Able to evade capture for years because of how carelessly the FBI managed information (which gave him the advanced warning he needed to skip town).

The most important part of the story is that it wasn't his hacking skills that made him so notable; it was his fluency with dumpster diving (finding discarded product manuals for the company's core equipment), but especially social engineering.

Whenever he couldn't figure out how to bypass security, he'd call around the company asking for names, phone numbers, and terms the company used so the next person he talked to would assume he was an insider and answer almost anything. It was so simple, but ruthlessly effective because we like to share. We like to help and there's nothing wrong with that.

There's nothing wrong with being helpful - quite the opposite in fact! But the key is to know who you're talking to and never offer more than is warranted for the situation lest you be taken advantage of.

Once Kevin was released, he started a security company and published this book to help teach people how not to fall for the tricks he (and many who followed him) used. A vital part of any security-minded professional's library, The Art of Deception will show you how to defend against tricks used to convince you to violate your own security.

Tags: , , , ,

Loading...

If you want to learn more about my professional background, click here to learn more.

Check out one of my guides/tutorials:

internet safety Tutorial
|INDEX|next: Online Addiction

General Safety

Avoid fake and nasty websites with my search engine trick.
Watch out for online addiction. Getting lost in fun online activities can be just as addiction as any drug.
So you want to write, publish, or share information online? Be careful. Things you say may be lost or forgotten, but things put on the Internet never are.
Don't fall for the well-known (or the new scams either) bad guys use to trick you into give away data or money.

Account Protection

Want to make an account with some online service? Read this first!
The newest, biggest risk online? Account hijacking! Don't become a victim by allowing your account to be taken over and learn to recognize when someone else has been.
Be sure transmission security is active before entering a name, password, credit card number, or other important information online.

... or check out any of my other guides and tutorials by clicking here!

How to Avoid Bogus Websites

There are bogus websites out there hoping you'll hit them by accident or using phishing to trick you into coming to them. Learn my simple trick to avoid these sites!

[Click for full description]

Online Addiction

Concerned about online addiction? You should be. Learn the types, the signs, and the preventions.

[Click for full description]

The Consequences of Posting Online

It's fun to post online. What you think, what you feel. But words typed and posted on the Internet can come back to bite you more than anything you could say with your mouth.

[Click for full description]

Tricks and Scams

Just because you won't willing give up data doesn't mean that I can't trick you out of it. Don't fall for these well known tricks!

[Click for full description]

Account Creation Tips

When you create an account with an online site, you should know a few things first.

[Click for full description]

Account Hijacking

One of the newest threats we face is the risk of someone getting control of your online account and using it against you and the people you know. Do everything you can to prevent that from happening!

[Click for full description]

Using HTTPS For Secure Login and Payment Online

Making online accounts is useful and fun, but doesn't mean much if someone can capture your login information and use it against you. Make sure to use this simple trick to prevent that from happening.

[Click for full description]