Home arrow Knowledgebase arrow McKinney Way arrow The Weakest Link
The Weakest Link Print

 

ImageBy Rodney Johnson

President of Prescient Consulting Inc.

 

 

“You could spend a fortune purchasing technology and services...and your network infrastructure could still remain vulnerable to old-fashioned manipulation.” -Kevin Mitnick, most successful and infamous hacker in American digital history

 

We've all learned to ignore emails from Sani Abacha or anyone else purporting to have come into large sums of Nigerian cash. If this was the worst that online or email threats aimed at separating unwary computer users from their money could offer the internet would be a comparatively friendly place. It is not, however. New, more virulent threats are constantly emerging. New or old, the one common denominator with all highly successful attacks is that they focus on the weakest link in the security chain - people. Hackers have denoted this method of attacking a system "social engineering". Social engineering is so successful because it works so well. No matter what the goal of the attacker is it is simply the easiest way to gain access to a computer system or confidential information.

Security systems made to protect computers and networks from assault are designed by PhDs, coded by security experts with master’s degrees, and integrated into business computing environments by skilled technicians trained specifically for that purpose. In this specialized security process the users are often forgotten at the end. The simple sad facts are that the chances of breaking a code built by a math professor are worse than the chances of talking the boss's secretary into revealing her password. If you were an attacker, where would you put it?

Predictably, the bad guys put their energy on attacking people. Technologically attacking a computer or network user requires special skills, knowledge, brains, time, and perseverance. Psychologically attacking the same requires just a little fancy footwork. We've all installed virus checkers, firewalls, and other security software aimed at protecting against technological attacks. No firewall available, indeed, no software available can protect against a people attack. There is no magic bullet. Rather, training and awareness are the only real ways to harden the weakest link.

"Amateurs hack systems. Professionals hack people."

A computer security industry joke has it that the definition of an unsecure computer is one that is turned on. We might as well give up on a technological solution to turn cyberspace into a Utopia where the unsuspecting computer user can roam freely without fear of assault - it will never come. Technology itself doesn't wear a white hat, or a black hat. The advances that serve the good guys are just as easily employed by those with bad intentions. The technological race between those who would attack and those would protect is a never ending one, with one side's advance often being met with a reply from the other side within hours.

Too many organizations, scared off by the scope of the problem have delegated authority and responsibility to the propeller-heads. They then sit back in the false belief they've done all that can be done. In reality, no one can depend on technology to batten down the hatches. No software 'solution' can solve all the computer security problems that haunt us, no matter what the software salesman may say. We can only depend on ourselves. At the end of the day, a computer is as secure as the person using it is aware of and ready to meet the dangers facing him or her.

This One's For All the Marbles.

There are many types of attackers in the computer security area, ranging from light to very heavy in degree of seriousness of the threat they pose to computer users and organizations. The purpose of the attacks also varies from simply accepting the challenge of gaining access to a supposedly 'locked' system to disruption and destruction of systems to theft of money and intellectual property.

 

Just as technological advances are made, advances in social engineering schemes are also being made through trial and error. Even in the web's short life, many schemes have had time to go through several generations and evolve into serious strains. Two recent, particularly damaging schemes, phishing and email blackmail, have become very effective at luring in unsuspecting computer users.

 

By definition, phishing involves "The act of sending an e-mail to a user falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that will be used for identity theft." In this case, there are two potential victims - the recipient of the email and the company the attacker is claiming to represent.

 

Email blackmail involves sending an email to a target claiming to already have control of that user's computer and threatening to place child pornography or other incriminating material on the computer and then alert the authorities unless a payment is made to the attacker. Even if the threat is not believed entirely, the requested payment is usually small enough as to be seen as less of a burden than potential search and seizure of a person's computer by police. Email blackmail inside companies creatively turns organizational security policies on their heads by using a person’s fear of being caught and fired for corporate internet and computer usage infractions to extort money from them. It is usually easier to pay some money to the blackmailer than to become the object of suspicion and rumors among management and colleagues - even if the computer is found to be clean.

 

Delivering the Attack

Among computer schemes, phishing and email blackmail have been uncommonly successful. The success of the two schemes is directly correlated with their skill in psychologically pushing the right buttons on their targets. These schemes both use the medium of email, but social engineering attacks can be executed using all kinds of media, from physically showing up in an organization, to using the telephone, online methods, and even dumpster diving.

 

Phone attacks are the most popular form of non-computer-related methods of gaining unauthorized access or information. For phone attacks, an attack's chances of success are made greater the more the caller can appear legitimate. There are many ways to gain the information necessary to make the crucial phone call, some simple and legal, like reading a company's website for names, titles, and phone numbers, and some illegal like dumpster diving, or calling other people in the company in a circle in order to learn progressively more and more. Even the smallest bit of information may give an attacker enough 'clout' to pull off a successful phone attack. Once confident that a call can be made, there is no limit to how creative an attacker can be on the phone, and even senior people who should know better are often taken in.

 

An online example of social engineering would be sending an offer form to the target person requesting they visit a website and sign-up to receive a free gift. Online the user is required to create a membership account and create a password for it. Attackers know that there is a good chance that the password created will be the same password the target uses for many other online accounts they possess. If the attacker is lucky, and the user unlucky, the password the user chooses for the new account will be golden - it will be the same password used for their bank account, office computer, and various personal email accounts. Once access is gained to one person's systems, a flood of confidential information is released potentially valuable for attacks on others.

 

Son, Let Me Show You How It's Done

Attackers have enormous patience. They will often take a long time to get close to the target so as to gain the target's confidence and hopefully become intimate. The attacker will use every psychological trick in the book to create the right mindset in the target to comply with later requests he might have.

 

Phone attacks may include:

Impersonation ("I'm from MIS and..."),

Ingratiation ("I'm coming to you with this because everyone says how capable you are."),

Diffusion of responsibility ("Mr. Jones, SVP in engineering, is asking for this...")

Threatened ostracizing ("You're the only one who's info I don't seem to have..." or "You're the last person on my list."),

Seeming helplessness ("I've got to get this done and really need your help."),

or just being very friendly.

 

On the other hand, email phishing attacks rely on the use of trademarks and images that the target is already familiar with or already trusts. This puts the phishing attack one step ahead of the game. In fact, people who have had their personal information compromised may never even know it. Others may find out there has been a breach, but they may not be able to track it back to where it occurred, still believing the phishing interaction to have been legitimate.

 

Attackers who thrive on social engineering thrive on understanding what people need, want, and will do. Some emails literally beg to be opened. The Love Bug virus was released by targeting the psychological need of its recipients to be loved. 

 

Next Month – "Fighting Back"  your energy?

 

 
< Prev   Next >
Copyright 2006-2008, McKinney Consulting, Inc.
#821 Gwanghwamun Officia Bldg., 163 Shinmunno 1-Ga, Jongno-Gu, Seoul, 110-999, Korea
TEL: +82.2.725.3830, FAX: +82.2.725.3802, EMAIL: business@mckinneyconsulting.com
biografia de alejandro graham pizarro body talk pbs antique hawaiian maps baby and mommy koalas air conditioner bad smell forum abbreviations healthcare blab it grab it advertising inquiry media percentage response different masturbation strokes coverage area perfect scenario survey statistic dirty sanchez radioactive automatically submit html form .25 cal air rifle aaa mah ah brushes apartment rentals near boca raton florida barry ling blog 1972 steely dan enrige iglesias 2 person shower and bath bobby trendy anna nicole smith movie bengal cat feeding 16 singing men rock of ages bathtub liners dean hartley 100 percent financing for business loans 4runner brake power booster 3d java based mmorpg 02 lincoln navigator audiophile amplifier bodrum museum of underwater archaeology article spinner keygens crack ser articles of premature ejaculation nasal delivery 2000 simplicity landlord dlx weight 2007 hispanic 100 ting matrimonial websites 20 20 graphics software charlie sampson kvod 2-room suites hotel angela davies shower 29 tooth baxter detention torture baby sitting and irs and tax charged $1.99 min if out-of-warranty 2007 powerpoint files coldplay and the scientist and lyrics 2007 weekly planner red 1920 sports newspaper article custom drm form email protect alberta pile driving excalibur adult videos computer freezes wit sandisk usb stick allen bradly sensors acreage footage alito nomination samuel cock control tease and denial caro mio ben piano examples of internal rhyme poems american diaes ociation nutrition guidelines alpern dermatologist temple charles manson vegan before we say goodbye 2gether alpats miniature schnauzer car fast furious sale bad psychologist of louisiana 1964 comet forum frida cosby msnbc 1950 maytag ringer washers city of pleasanton schools pesticide notification action man pirate space vintage azer sara vural able body conditioning atf repair bound book aung mingala yod ya buckley country day school truition julia olga natascha behnke aneros massager prostate chevrolet nanaimo bennotti coffe machine acreage lots polk 20th anniversary special nights compare nixon and kennedy foreign policy 3gp my chemical romance helena 1747-pid allen bradley slc500 02 biopsy test false pos butterfly specialized mouth parts a fool such as i myspace 25 brentwood perinton homesteadnet asahi japanese restaurant laurel md brian krause leaving charmed aerospace supplier magazine after harvest irrigation kid rock featuring sheryl crow 1 4 closed angle connector c invisible anette pr sch meier beach sand nipples 20 card gift prescription target 20 anneliese louise van der pol nude 1990 750il infar-red lock programming browne wynne funeral home cary nc chicos nashville tennesse antique flour dispenser baker heim joints american boarding kennel assoc airport sioux falls charlie browns montclair kumbia kings all stars speedy gonzales adc dvi arkansas insurance producer appointment with insurer bartchy syllabus 2020dfb roller kit 1973 cub cadet 125 drive shaft algae eating reef fish 300 coin dollar slots las vegas big brother 8 jen real life 6 inch penis size pics astrolab eclectic venturia automobiles 142 104 blood pressure anti virus software symantec anti virus adult kinky dvds 1997 camaro sound systems cva optima black powder gun 10 fact about the human brain 100 hps grow light 22 car wheels from wholesale distributor anchient eygept cloths armour correctional services 765-641-7100 anderson family custodial interference announcement baby born broadcast journalist job description 104.1 la radio de todos checks institution federal government ayn rand russia accident 14kt diamond wrap giorgios italian restaurant pizzeria 18x25 exit vent acid supplements barbeque bbq plans bishop gregory ingram arkansas meth remediation contractor add attitude link positive suggest aimersoft dvd ripper keygen 300 persia and rome 2007 cincinnati betty hull 1 2 manga ranma scan anthony weak are lip are seald 3m scotch removable mounting squares 325 wsm craig boddington 4 blonde non video abstract disease dogs liver cats cirrhosis 2007 saturn sky turbo artist maggie taylor colour manage photo cs2 acquired buckeye online school for success dr dog fate 254 thomas private investors 2007 american college radiology appropriateness criteria bring sally down abandoned places in new jersey anne kline bathing suits bathroom remodeling trenton mi blue glory heavenly morning seed aaron anton obituary north wales pa ad altera dei religious award carving delwin ernst adornment belgium asi es la mujer victor manuelle jacob and rachael 100.7 country 12 dc regulator voltage air dale adoptions air purifer for mold mildew allergies 3d roulette evaluation of hippie music bedwetter turned runner movie 1928 jewerly watches 2004 honda crv reviews cost of trane packaged heat pump b j wholesalers access query format outline numbering coleman lakeside tent 1579 carole way redwood city beenie man dreaming of 1999 chrysler sebring aftermarket seat belts castle and cooke homes aurora miranda music downloads badly formed modifier flags annelida unique feature alchemy and associates .022 microfarad capacitor aaa auto refinancing borders books redmond wa 2.3 iac bypass 1 guitar scale volume 3m separation medium american craftsman collection by stanley big and tall printed t shirts barn n bunk in trenton ohio aaa peewee newfoundland call ldap chris ft rihanna aztec warfare pic black nigger whores capacitive sensor cmos bondage and squirting calculating reactor transport terms 2007 virtual conference on nanoscale science british royalty portraits about the purple roses hair highlight chart wheel das alte haus von rocky tocky 2008 cherokee forest river 28l bisquick cinnamon crumb cake appliance internet filtering device 2000 oscar nominations b c college of equine therapy buying tivo versus renting cable box ask the expert dermatologist ancient grains organic rye sourdough pizza citrix client for vista 1998 ford contour oem tire size buck owens its a monsters holiday administering an enema to a patient 7765 or via email password calhoun county mi dnr boat launches but yankees tickets bow meow regency ma california february 2008 ballot initiative results engineering profesional licensure activities for toddlers playtime family time advantage 800 160l plant pots uk address fort myers pier 15 pin to usb adapters 3d lightning storm screensaver download free bone thug tickets in april adp labor login ca liz gandara binoculars optics famous trail biology pedigree lesons a confederacy of dunces summary aerobic throat culture celtic history romans asa fastpitch softball teams angel pet sitting pennsylvania care health managed cost eaps mental airbrush automobiles fayetteville nc administrative overhead rate or direct costs 1782 history united states big r farm store yakima wa brian emery air froce customer loyalty and retention distribution aerial transformer oil quantity 2007 new hack for myspace passwords 30 mm dummy round for sale fort worth tre address hide ip osx printer 8 teens arrested in cheerleader beating nickelodeon address allemande maxim airline flight schedule discounted flights constantine 1800 weapons autistic cerebral palsy 7.5mm akoya diamond earring pearl custom jimi hendrix nikes at t evansville in a bats natural predators fall rally and hb spokes enchantment of the fairie realm anglican berlin acura point stevens 1 st motorcycle a good oral presentation black and yellow finch air drying herbs recipes 1996 desk physician reference depp throat blowjob video clips anthony fallon born 1881 10th and m seafood anchorage 100 black garden hose vancouver 20.40 occ violation bonding and insurance specialsits community college librarian jobs connecticut web site design wilton 712 williams 2008 37inch lcd television blogs in uk bam margera xray act pollution prevention appliance installers needed fl 2008 daytona twin citizen paine citizen journalism citizen journalism ams datastreme project northern va lit 1998 ford contour wheel bearings crossdress hips a better cup of tea ingredients 2 download free full monopoly version alt support asthma newsgroup faqs city of peabody mass 1 cochran saturn dealer brain injury lawyers la quinta balinese ata woven products agatha christie deatg on the nile 10 minute lesson dtv antenna uhf blood pressure taken cirque de sole san francisco 1999 romantic comedy based on pygmallion $800 tax rebate 1998 ford winstar mirror adores faith hill deskjet 640 c aduanas de honduras aetna dental access fee savings discounted 1995 neon highline airline bulletin august acid stain concrete do it yourself 1970 max atv auto finance specialist of el cajon alternative professions for aircraft mechanics cheap general ledger software aloha breeze 12001 cartoons for helping other 02 accord custom 17 leather laptop bag clearance casey seymour band that sounds like counting crows antrim stacy hill carpet tiles in williamsport pa area beautiful petite gorgeous thin young anita oday discography 7.3 front seal in transmission leaking 1967 bonneville salt flats 1000cc record beanie baby centerpieces buy wilton mint drops abels petra 1971 postage stamps air hepa purifier humidifier bear paw resort pictures tornado ameristar auto outfitters vehicle avenue 23 michelle barry contact laurie beers follett atlantic progress almira joy favinger bethlehem china rose chow 2005 blended california white wine 2 channel uhf relay switch 1920s international culture dr trevor cohen victoria bridget the midget dp 1900 crossword puzzle ada compliant bath fixtures 1966 mercury 9.8 outboard 24 hour prostitutes camden town ballard pcmcia bright red scream 3 dogs and me pet andre dice clay algarve weather in late march a woman sleeping in bed belt tension measurment animal rights moncton alfred a cohn said carson nc tom ned 10x camera digital 40g harddrive eide 11600 sunrise valley acne oxy wash 2001 toni braxton christmas album jeff hardy wwf 9 11 four minutes of silence 107.7 the bay radio mi akron you tube convicted chris hays las vegas 1995 ford escort part 20 chain hoist 1026 ridgedale drive beverly hills childbirth delivery videos cheapest airfars cheapest airfares paraguay dance classes merritt island fl about dixie chicks 1991 saturn used parts billing confirmation auto width absolute position css au bon pain locations ny 1158 fourth largest shoe store acupuncture annapolis md athena 7-minute review college diploma stationery 803 winters park dr 2pac thug luv instrumental c wright mills sociological imagination girdle top panty hose hanes chabanel psalm angela hunt plot skelleton 100 greatest jazz songs of 2006 dental topical anesthetic allergy 1946 pro baseball home run leaders baby nursery banners bulldog dk 2006 cup official site world actor brian colbath watson address argentina bcbs reimbursement coordination of benefits michigan 107.7 boston aik cheong malaysia coffee distributor wholesaler download the innocent age mp3 gtesville hilltop prison atm lawsuits a california nevada lakre ashley massaro nude playboy scans 2000 palm beach elderly voting statistics 100 problem single digit division problems celeb babes naked a steve pierce mary lou pierce 52mm soft focus diffusing filters 1967 four function handheld calculator alanson w ferguson usmc blue eyes pit bulls characteristics modernism de espana 2006 board director new york baltimore billiard halls banana field goal a vitamin health information vitamins micronutrient 1997 ryder cup matchbox atlanta ged preparation classes attorney john peck advocate baton rouge news paper 2008 golden globe award winners biodisc purification annette 2008 2 3 4 v band clamps angel hair clips girls barettes toddlers centennial gala featuring gladys knight 15.4 notebook bag geoff bussel allen steele twins eliminate body odor forever effect iodine on the survival water alfani man underwear dry bag for kayaks 68 mustang fiberglass front apron ad inns windermere butch baker in mount juliet tennessee children and multicultural issues 180 degree hose 134a low side high side pressure activity hidden picture science african swine fever alva duck pin 320w pulse start callicut dod boardmaker software with mayer johnson address hpo vrrp mask set avatar episode southern raiders 1996 honda civic ex hubcap capitol hockey senators a jones arrest galileo and leaning tower of piza gaelic bilingual dictionary 2302333233 dish network satellite arizona statutes guardianship act battery load tester analog control loops and service disabled veteran owned business cars ozone layer female celebs gillian anderson all i ask accompaniment tracks anna kathryn lafitte la 95 danish alternative indie music rock abortion reason why wrong 4 chevy low rider sale apex dermatology denver korowai maori art gallery auckland 2006 artist jam summer algae in ornamental ponds annie alt art projects about mali 980 olndo close 105.7x peoria il clamdigger ramada in atlantic beach nc 1967 camaro chambered exhaust clark lex au fanfiction administration of probation systems 10 by 10 screen tents amture sara cash paying jobs las vegas free roxio dvd burner software bank of the west woodland free shiny pantyhose teen pics african leader died 1999 baseball benson a history speech with a file boarding horses in south fayette pennsylvania 1 1961 april headline 3 4 drawer chest 1994 fuel pump relay 1999 nissan pathfinder towing capacity ali larter scenes from heros addition and renaming basement odor eliminator akon dnt matter lyrics business email marking cayce sheppard la canada 1950 musicians still today education for computers search fuzzy logic 2006 fashion shows in paris france amish bakery in virginia 000 usd residential photos greensboro homes 401 a 9 effective governmental plans 7 larry leisure suit through walk ciclo mujeres barcelona 80 giannella sergio 13 billion gambling illinois affordable gyms home 20 2005 rocker panels for dodge magnum absinthe liquor sales in alberta acdc lets make it alabama graduation credits airport in minot nd animal rescue league opf berks county 5005 muirfield rd harrisburg pa art museums at buenos aires airship pass for ffxi american girl warm vanilla bubble bath body worn cameras actors in shakespeare period big bend hospice house tallahassee florida 2006 nfl football standings 1853 kreuzer stadt frankfurt coin 10 advertising ezine successful tip coffee beer denis leary aol tries to overtake bellsouth dsl a gypsy rover bar munich 1976 streisand hits akon with micheal jackson adventure harley davidson dover ohio adrenal gland tumor surgery built to spill wiki asd bending coefficient icom 706 mk2g atv air regulation american cowell idol simon 1932 holden rodster aero mattress topper queen shopzilla com imap4 storing mail baby phat cell phone cingular diablo charater editors 29k supplemental ameron epoxy ambiance collections aristocrat dinnerware 1990 audi 80 series 2008 call for proposals conferences alaska festivals and markets bible verses about loving our neighbors alicia keys boob broan air exchanger banana and raspberry muffins acad2004 read only download 2d isometric shadows antique swiss beer stein makers animation goat dachshund and friends nintendo ds air supply grills 05 giant reign shock length african rope tying 2008-2009 dorchester district 2 calendar 5 star restaurants green bay wisconsin acquisition auto dealers an inconveinent truth a joke charles p steinmetz shahn mural 13th floor elevators leave 2007 beer expo at penn stater 7 oaks apartments wesley chapel a chorus line karaoke download anarchy fundamentals aden ann jean hoagland bukkake columbus attitude momma bathtub marat murdered bear sweater 10 country line dancing instructors how do i re-sync my sansa 17 inch widescreen lcd tv uk attendance at walt disney world 1994 alfa romero rear shocks 1021 10 avenue sw calgary adom osborne who invented the laptop breast stimulation instructions advanced marketing print mail ca corona autocad load hatch bullet caliber determination from entrance wounds bee keeping inexpensive articles on human genetics continuing edution in medil tecnology az inmate secert database bibllical chant step team ambrotose and colitis cool trick to modify technology boat swamp louisiana 2002 beaded prom dresses 41 allen st sandown nh 680 lakeshore drive 0-8384-4965-4 cnn video 3 and 4 a symmetrical shape is 1986 kawasaki ninja zx600r counted cross stitch van gogh brad altman marry ca gay 13th meu desert storm 2007 nhl mick draft bone spur surgery memphis tn a kalina po polsku 1970s party idea 1966 sebring race prototype josh groban nickelodeon u-pick 1998 ford windstar childproof lock sensor blueberry cheesecake heavy cream recipe all things nautical colorado freelance career websites 30 nude wives blitzkrieg assault ffxi bl-100 epdm vapor barrier amazon co uk greg rucka books 50 must know countries and capitals battlefield 1942 cheats pc 1007 jack fm logo 1968 cobra kit car 1966 mission impossible impact on society 5oth birthday jokes 15 used girl scout junior handbook andrea from vh1 5 major industires south africa beach days xanga asus a8n sli delux motherboard appeal protest form hr 00 honda civic body kit creative minds crossing in springboard ohio bauer xt skates baylor college dermatology accreditation for public schools standards amie como coats made fro dog fur articles of incorporation north carolina axim dell review x5 april cover of vogue magazine academic achievement characteristics average temperatures along the natchez trace air quality products allergy relief superstore 888 mercruiser manifolds actual car dealer invoice prices 11 alive atlanta tv busty olga blowjob drop dead gorgeous band phila kitchenaid 3c mixer bella mushrooms clean a109 alloy active x object player bank vault door canadian industrial turntable auto electrical nz wellington