ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Mitnick warns on dangers of social engineering

David Braue ZDNet Australia

Published: 04 Mar 2005 12:15 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Companies eager to tighten up their information security perimeters should focus not on technology but on teaching their employees how to say 'no', ex-hacker done good Kevin Mitnick told a full house at Toshiba's MobileXchange conference in Melbourne, Australia, on Thursday.

Mitnick became a cyberspace legend after his success in penetrating networks at major telecommunications firms -- including Pacific Bell and Motorola, Nokia, Fujitsu, Novell and NEC -- led the FBI on a 15-year manhunt that ended when his 1995 capture put him behind bars for nearly four years. Older and seemingly wiser, he now uses his skills for good as a Los Angeles-based security consultant, stopping in Australia briefly to address the crowd at the annual Toshiba event.

Many companies invest heavily in security technologies to protect their networks, but Mitnick was quick to point out that even the tightest technological barriers never stopped him; rather, some carefully planned social engineering -- or even a bit of Dumpster diving in one's spare time -- can often be far more effective at penetrating the weakest security link at most companies: their people.

"What you can find in the trash is simply amazing," said Mitnick, holding up a "souvenir" from his earlier days: a printed directory listing the name, phone number, email address, direct reports and other information about every employee in the company. "People throw out notes, drafts of letters, printouts of source code, printouts of project documentation they're working on. In some cases they even write down passwords and access information, or calendars that list every person that person has talked to or met with".

This information provides invaluable assistance to hackers keen to worm their way into a company by, say, impersonating an employee and calling the internal help desk, or dropping into the site and pretending to be a business associate. Because people hate to say no even when they're suspicious of a well-presented stranger, Mitnick says, smooth talking has gotten many a hacker far closer to a target company's network than days of brute-force technological attacks.

Modern technology is an enabler for such attacks: if a hacker can worm his way into a conference room for just a few minutes, for example, an wireless access point can be plugged into an out-of-the way network access point, providing an open back door into the network even when the hacker is parked outside the building.

The solution to such security vulnerabilities is easy to understand, but often hard to implement: develop clear security policies for issues such as treatment of strangers, handling of information and access to physical facilities by visitors. In suspicious circumstances, teach employees to fall back on those policies rather than trying to ad-lib their response or give in to their natural reticence to accommodate the hacker's requests.

Even a simple request for contact details, so that a company employee might call back the person requesting assistance, can be enough to make many hackers turn tail and run.

"We can't expect our employees to be human lie detectors," Mitnick said. "One of the most difficult challenges in corporate cultures is getting people to modify their politeness norms. Social psychology has found that people should generally pay attention to their own discomfort; if something doesn't feel right, or it's nagging at their gut, they'd better check it out. They're not always going to remember a security policy, but what you want is to come up with some very simple protocols that will trigger employees to refer to security policy. The only people who are going to object to this are the bad guys".

David Braue reported from Sydney for ZDNet Australia. For more ZDNet Australia stories, click here.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
84 out of 139 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Junior Developer ( Java , SQL , Oracle , Sybase ) - London

Calypso Technology is an equal opportunity employee (EOE) and strongly supports diversity in the workforce. In addition to our headquarters in San ...

Support Manager-International IT/Conference Co.-35,000 City

Support Manager-International IT/Conference Co. City Manage the support of this international IT/Video conference organisation that has seen huge ...

Internet Operations Analysts

Penetration testing (e.g.preventing hackers accessing critical systems and information) An interest in internet technology is of course essential. ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment