Showing posts with label social engineering. Show all posts
Showing posts with label social engineering. Show all posts

Tuesday, January 27, 2015

How To Get Someone’s Password


   No matter what else is going on, it seems that I keep circling back to the subject of passwords.  I’ve covered this topic many times, including here, here and here.  But it’s a new year and a new week and passwords are in the news again

   I’ve jokingly said for many years that the easiest way to get someone’s password is to just ask them!  What I mean by that is that many people will inadvertently give up their userid and password via a Social Engineering attack.

   Wikipedia defines Social Engineering as the "psychological manipulation of people into performing actions or divulging confidential information. A type of confidence trick for the purpose of information gathering, fraud, or system access, it differs from a traditional "con" in that it is often one of many steps in a more complex fraud scheme."

   An attacker can send a phishing email that either directly, or via a link to an online form, asks for a password.  They can call the victim on the phone, or call a help desk impersonating the victim.

   Or, they can just walk up to someone on the street and ask!...


   And this is certainly not the first time something like this has been tried.

   There you have it!  So protect your passwords… use a password vault; use different passwords for different systems; use strong passwords; watch out for phishing emails and calls, and; don’t give your password to someone else!

 
   For extra fun, try one of these phishing quizzes.  See if you can identify the imposters!  And reread this post on phishing.

Tuesday, September 23, 2014

"Who Am I?" (or, Who Was I?)

   I like the story of Les Mis.  I definitely like the musical.  I was not wild about the movies.  The book is definitely a good, and very long, read (or listen!).

   At it's core, Les Mis is a story about Identity Fraud!  It's the story of a man, seemingly wrongly convicted, who operates under a false identity in order to be able to live his life.  It's a common literary theme, used in stories like Martin Guirre, The Count of Monte Cristo and Matchstick Men.  In "olden times", Identity Fraud penalties were very serious. Today... not as much.  Last time we started a discussion of Identity Fraud - we'll continue our discussion of this topic.


   Breaches of online merchant websites and databases get a lot of media attention.  But there are many ways ID fraud is committed including:
  • Shoulder Surfing - this means someone looking over your shoulder, for example when you enter your PIN at an ATM
  • Dumpster Diving - it's amazing what people throw away
  • Mailbox theft - checks, financial statements and other sensitive documents get stolen from mailboxes
  • Stolen purse, wallet, laptop, tablet, phone - these all contain plenty of personal information
  • Social Engineering - be careful about what information you give out about yourself
  • Phishing - email or phone - con artists will call or email pretending to be your bank, law enforcement or other authority and ask you for information.
  • Social media - do you really know who your "friends" are?... there are all kinds of requests and information gathering schemes
  • Copy-cat websites - it's pretty easy for scam artists to create a fake site that looks just like your bank's website, perhaps with a misspelled URL like nationa1bank.com (that's a one instead of an L), and then collect the info you enter.
  • By known or unknown thieves! - some ID thieves know their victims.

   So many choices!