TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

The Man Who Hacks Your Employees

81 pointsby softdev12about 10 years ago

8 comments

AlexDangerabout 10 years ago
Not sure how it is in USA&#x2F;Europe - but in Australia, some of the biggest banks&#x2F;telcos still ring up customers (from private numbers) and ask for <i>all</i> your personal details to confirm your identity before proceeding with the call. Some even ask for plaintext passwords over the phone. At the same time they have big warnings on their webpages about phishing and how they&#x27;ll never ask for personal details over email.<p>More than once I&#x27;ve explained that providing all my details in this fashion directly contradicts the security policy of the banks, but it takes some convincing to get the phone operators to give you a number you can confirm is legitimate and call them back. Its clearly not on the call center script and they dont understand why I am being so pedantic.
评论 #9409032 未加载
评论 #9409997 未加载
评论 #9411001 未加载
评论 #9409072 未加载
评论 #9409600 未加载
Zikesabout 10 years ago
&gt; Let’s say the jolly IT guy calls you and he starts to ask you things that don&#x27;t make sense. That’s when a red flag should go up.<p>That&#x27;s an everyday occurrence in some offices.
评论 #9409459 未加载
Scramblejamsabout 10 years ago
He mentions putting a color swatch on the company intranet that changes daily as a form of authentication.<p>I wonder how well it would work to call people up and say, &quot;Hi, this is Paul from IT, we&#x27;re having some trouble with our intranet security color swatch generator this morning. You should be seeing pink. Is that right?&quot;
评论 #9409151 未加载
评论 #9413284 未加载
eyearequeabout 10 years ago
His social engineering contest at defcon is always awesome to watch. It&#x27;s incredible to see the big companies give out such internal information. The social engineer is inside of a glass protected booth and the crowd can watch and listen in. They have a points system where the harder to get info gets you a higher score. Ex: a high score was given if you could get them to hit social-engineer.org from their browser. One guy told the person on the other side of the phone that it was a social network for engineers. Also: Make sure To check out the contest on Friday&#x2F;thurs as they can&#x27;t really do the live over the phone hacking on Saturday&#x2F;sun as most businesses are closed on the weekends.
评论 #9411226 未加载
ChuckMcMabout 10 years ago
This is a scourge. And of course most employees who get a call from someone purporting to be part of the company have a reasonable fear of creating problems at work and so often seem to err on the side of giving out more information.<p>The sad thing is that as we open up more and more ways to &quot;do&quot; things remotely (like move all your checking account funds from your account) the more danger involved. In many ways this makes the whole requirement that you authorize at a specific terminal in a secure space make much more sense.
评论 #9411086 未加载
ibradabout 10 years ago
If anyone from IT calls you, you should be able to call them back at their extension. Or that&#x27;s a red flag.<p>We used to have fun with William the &quot;Windows Tech team agent&quot; (from India) . He (They) would call us at least once a week. I think they might have had a successful attempt otherwise why would they keep calling.
jmckibabout 10 years ago
&gt;WSJ: Hold up. How can I get a free plane upgrade?<p>&gt; MR. HADNAGY: Airports are always stressful. These ladies are always getting yelled at. If we make someone happy before we can ask for a free upgrade, that could work.<p>So now the question is: how do you make the agent happy enough to give you an upgrade? Just be polite?
iizarcabout 10 years ago
&quot;LinkedIn: I have everywhere you’ve worked. Everywhere you went to college. Facebook: I have your family, your wife, your kids, your boyfriend, your girlfriend, your last vacation. Twitter: I have everything you’re doing throughout the day. If you’re on Foursquare, I can geolocate where you do it.&quot;<p>This is so true lol. Many people don&#x27;t realize all the valuable info they put up on social media. Great article btw.