The Art of Deception
The Art of Deception is extremely easy to understand and actually fun to read.
The first part of the book, Behind the Scenes contains the first chapter, Security's Weakest Link, which describes through many examples how and why the social engineer is able to so easily manipulate people to get what he wants.
Part 2, The Art of the Attacker, contains chapters 2-9, which describe various ways a social engineer can manipulate people over the phone. Each chapter tells of a different method that could be used to gain information. Each chapter also contains at least one example.
Part 3, Intruder Alert, contains chapters 10-14, which tell about different ways a social engineer can get inside a company, whether physically or through an internal contact. Each chapter contains at least one example.
Part 4, Raising the Bar, contains chapters 15 and 16, which explain how a company should create their security policies and training to prevent the social engineer from gaining access to sensitive information. These chapters are definitely more geared toward the executive, security analyst, or other specialist, as they contain specifics on what new policies should be implemented and why.
The last section in the book, Security at a Glance, contains some charts and information which should be read over by a more general audience, such as employees and other people that may be contacted by a social engineer.
And one sidenote: there's a nice little foreword by Woz (Steve Wozniak).
The Summary Although this book is geared toward the company security expert, this book also has appeal to anyone with an interest in social engineering. I found it to be a quick and fun read. As a social engineer, this book taught me new tactics to try as well as ways that my targets might be prevented from giving me information I seek.Table of Contents
Foreword
Preface
Introduction
Part 1 Behind the Scenes
* Chapter 1 Security's Weakest Link
Part 2 The Art of the Attacker
* Chapter 2 When Innocuous Information Isn't
* Chapter 3 The Direct Attack: Just Asking for It
* Chapter 4 Building Trust
* Chapter 5 "Let Me Help You"
* Chapter 6 "Can You Help Me?"
* Chapter 7 Phony Sites and Dangerous Attachments
* Chapter 8 Using Sympathy, Guilt and Intimidation
* Chapter 9 The Reverse Sting
Part 3 Intruder Alert
* Chapter 10 Entering the Premises
* Chapter 11 Combining Technology and Social Engineering
* Chapter 12 Attacks on the Entry-Level Employee
* Chapter 13 Clever Cons
* Chapter 14 Industrial Espionage
Part 4 Raising the Bar
* Chapter 15 Information Security Awareness and Training
* Chapter 16 Recommended Corporate Information Security Policies
Security at a Glance
Sources
Acknowledgments
Index
You can purchase The Art of Deception from bn.com. Slashdot welcomes readers' book reviews -- to see your own review here, read the book review guidelines, then visit the submission page.
Doesn't the US DCMA NOT allow for tools that bypass security? I wonder how soon it will be before someone tries to use the DCMA against someone who used social engineering.
"If you are on fire you can just stop, drop, and roll. If you fall into Lava you are just dead." - my 5yr old daughter
there are always people that will have contact with them from the inside
Can't you get cryptographic keys that are sealed inside a black box device so that no-one can access them? Couldn't this sort of thing be done for at least some hardware?
Oh dear, I think I've just justified security through obfuscation.
Dear Amazon.com,
I would like to get a copy of "The Art of Deception", however my grandmother needs surgery and I can't spare any money at the moment. If you'd like to lend me a copy please feel free to email for shipping information.
I, and my grandmother, thank you.
grubby
Trolling is a art,
The Register ran a review, along with the original first chapter of the book (which was cut by the editors).
The first chapter is (or rather, was) a short bio and history of the Mitnik case. Interesting to read Kevin's side in his own words.
The lost chapter
It is tempting, if the only tool you have is a hammer, to treat everything as if it were a nail. - Abraham Maslow
"Chapter 2 When Innocuous Information Isn't"
All the little bits and pieces of info can sure add up to a major security hole if they are collected by the right person...
As a social engineer, this book taught me new tactics to try as well as ways that my targets might be prevented from giving me information I seek.
You misspelled "criminal".
Now the key question: how much can you believe of what you read in the book? Well, about as much as you should believe coming from a man who obtained millions of dollars (1860 millions!) by lying, cheating, and swindling.
sPh
I mean look at an article on TechTV as far back as October 2001 that point out such human blunders as "Default installs of operating systems and applications" or "Accounts with no passwords or weak passwords"
Perhaps this quote from a Oct '02 SANS/FBI article point out the worth of this book where they say:
Which is why I think books such as "The Art of Deception" are as needed as biometric identification systems to secure your computer facilities.
healyourchurchwebsite.com - WWJB?
This isn't a review. It's a Table of Contents! Was the book even read?
Is generally the users. Excluding those who run open mail relays, most servers/sysadmins have enough brains not to run the file in their email coming with a message:
.exe/.vbs/etc entirely.
This iz a very fun game
I hope you anjoy it
I made this just for u
How users manage to continually fall for this idiocy is beyond me, but they do. My family is a prime example of this (they refer to me when something dies, but never listen to my "do not open attachments" rant): thus, they now get Mozilla and I'll probably block emails with
Just based on the chapter titles, I think tricks such as the "Let me help you", etc are probably some of the nastiest. Considering the many people who seem to know shiat about progamming and come for help, it wouldn't be hard to slip something cruel into your "sample code."
It's amazing how, after helping somebody directly with something for 30 minutes or so, they're suddenly willing to let me
a) Have root access to their machine ('nix)
b) Control their PC (netmeeting/etc windows)
Luckily I'm a nice person, but not everybody is so helpful as they appear. Social engineering is definately an increasing trend, which is leading to user pananoia. I still don't think that the statement "One of the weakest links to the most secured computer systems are the humans that operate them."
A good sysadmin will block a lot of things that lead to exploitation (unused ports, etc), and perhaps notice odd happenings/traffic. It's the operators of the less-secure systems (clients) that are at risk most often.
I read this recently, and although it's a pretty good introduction to the conman profession, I was a little disappointed in the lack of actual examples of clever hacking.
The book is primarily about social engineering. Most of the example crimes in this book could have been perpetrated by folks who had no more than a casual acquaintance with the inner workings of computers. In other words, Mitnick tells you how to exploit the stupidity of human beings in large organization, and not how to exploit weaknesses in operating systems and security software.
Part of this is probably due to court-ordered vagueness; the court obviously didn't want Mitnick spreading dangerous knowledge.
On the other hand, Mitnick is probably correct in his contention that the greatest factor leading to compromised systems is the naivete of the folks who work with them.
May seem like a nitpick, but isn't this "review" more of a "Table of Contents with brief description of chapters"?
Slashdot Book Review Guidelines
It's a knack, social engineering.
I've read the book, and just like some people couldn't sell food to a starving man, only a few people can pull it off.
Get one tiny piece of information from one person, another from another, and after a while, enough of those pieces make you sound like you are an employee. And we all help our fellow downtrodden, overworked employees, don't we.
EG. If you have an intranet at work, I bet you have a nickname for it. And if someone asked you for something from it, and said "I can't get to the XXXX today, not sure why, it seems to be down..." you'd probably go and find the info for them.
Get your own free personal location tracker
wow now even hacker's get their own books when they get famous. Seems to me that this will be just another security book saying the exact same thing as the other 200000 of them already in circulation.
Hey Bob, I have $100 to give you if you give me access to such and such a network..
Lets face it. The easiest way to manipulate the human element is wave around some cash. Many people will do anything for the right price, whether it's illegal or not.
Ah am not a crook! (\(-__-)/)
Chapter 1 was removed from the book by Kevin's publisher. It gives an interesting insight into HIS perspective on how he came to be known as Public Enemy Number 1 on the Internet, the feud with John Markoff, the Takedown film, as well as how he got into social engineering in the first place (getting free rides on the bus...)
The Register have it here.
"None are more hopelessly enslaved than those who falsely believe they are free." -- Goethe
Before seeing Slade's review, I read most of The Art of Deception at the bookstore and decided not to buy it. I agree with most of what Slade says. The book is mostly aimed at PHB types and doesn't say all that much useful to techies. However, as a security implementer, I don't think trying to install paranoia in PHB's is such a bad thing. They are often completely unrealistic about vulnerabilities, so it's good to open their eyes a little.
...and it seemed quite boring to me, probably because he was preaching to the choir when it comes to security people, as the book was geared more for CIOs and other management types.
He had an interesting way of presenting various stories of of how people can penetrate by switching to a first-person view of both the victim and then the attacker. It was a bit annoying how the "attacker" would be portrayed as 1337 sometimes, but it was an interesting approach, especially since some of the stories were possibly Mitnick himself.
Overall, though, I was underwhelmed.
The One Rule Of Chess You'll Ever Need: Don't play someone who carries a kit in their bookbag.
I'm reading this book now. Surprisingly, it isn't so much about technology and security. Instead, it is more about understanding humans. Despite the sterotype that geeks have for being socially incompetent, to be a truly good hacker using social engineering, you have to be good socially. Maybe not great, but pretty good. And, you need to know the right language and the right people to communicate with. Mitnik does a great job with this stuff and I am really enjoying the book. (However, I'm not so sure his tactics will work as well as they did a few years ago.)
Here are some pretty good resources for learning more about social engineering:
Social Engineering: What is it, why is so little said about it and what can be done?
Social Engineering Fundamentals, Part I: Hacker Tactics
Social Engineering: The Human Side Of Hacking
How to Download YouTube Videos
I didn't want to buy his book, but he somehow deceived me into buying it.
Now I'll have to read it to figure out how he pulled it off.
SmartCard security, ATM cards, and a host of other security solutions (not just along the card theme) already employ the "Something you have, something you know" security scheme in which sensitive things can only be accessed if you have both a device (usually containing some sort of identifier) as well as a password.
Another interesting version of this system involves a keychain or some similar device that contains a computer whose only job is to take some encryption key and scramble it every n time interval. The central sever is doing the same thing. The end result is that the user has to know two passwords - his normal password, plus a key that changes every minute or what have you.
hey, kevin! man, i just wanted to let you know that your performance in "Hackers 2: Operation Takedown" was outstanding! Do you consider acting side by side with Master P in that movie the high point of your career? Also, could you sign my copy of "Scream"? I thought you were great in that too.
What do you mean that was skeet ulrich and not you???
------
[insert funny
Am I the only participant to this forum who thinks that any admiration on Mitnick is admiration on a crook? As this book clearly seems to illustrate, the basis of his success as a cracker was his ruthlessness and willingness to lie and deceive people, rather than his technical prowess.
I.e. Mr. Mitnick is a criminal, who may or may not have extraordinary technological savvy; all those years in jail, and post-jail constraints, were surely well-deserved.
I also read The Art of Deception
I do not really know how to describe this book with its strange mixture of fact and fiction. 2/3 of the book are stories of social engineering in all forms and shapes. That gets a bit long and tedious long before you have finished the 245 pages of it.
The rest of the book consists of recommendations for raising the bar. A long list of things to do if you want to tighten security at your company.
So does social engineering really work? Yes, my guess is that most people will not know what hit them even if you ask them afterwards.
At the very least you should be convinced by Mitnick talking Steve Wozniak into writing the foreword (Kevin Mitnick is one of the finest people I know) and Wiley Publishing, Inc. into publishing what I consider a weak book on security. There are of course a few good points but they are too few and too far apart.
The leading Danish financial newspaper, Børsen, wrote that it should be required reading for people with an IT security responsibility. I can only say that if you have an IT security responsibility and still need to read this book you are most likely in deep trouble.
You should only bother reading The Art of Deception if you know next to nothing about the human aspect of security and then only if you really think you are safe.
Don't forget the first chapter...
Here: http://212.100.234.54/content/55/28835.html
Excellent reading.
The Art of Deception is extremely easy to understand and actually fun to read.
This "article" is an example of why Slashdot gets less and less interesting. It's articles are often duplicates stories already posted, screeds by JonKatz (a writer who fills a much needed void) or content free nonsense like this one.
This is not a review at all. It's just some guy commenting briefly on a book that's been out for ages. Slashdot is way behind the times and the review is worthless.
Why editors did you choose to publish this on the site?
John.
A important criterea in social engineering is to get a person's help, hell, even goodwill, without them realizing that you up to any skullduggery. If you're really lucky, they won't even remember aiding you.
the preceding comment is my own and in no way reflects the opinion of the Joint Chiefs of Staff
I loved this book. It showed in detail the
application of social engineering in ways
you might not have thought possible. It didn't
show a lot of heroic hacking, which was part
of the point. There were some good bits
on how to install trojan horses though.
I have always thought the easiest people to exploit (not that I do) are minimum wage or poorly paid employees at crappy jobs. You can sweet talk a lazy teenager and usually get what you want, but I think sweet talking an adult gets you more in the long run. Who do you think you could get better results from, a lazy clerk or a lazy manager? I'd take manager any day.
I was given an advanced copy of this book as I had done some work for Motorola and Sun Microsystems after Mitnick had broken into them and I thought it kind of glossed over some important info.
For instance he leaves out the famous ack flood attack which was used to break into Motorola by utilizing a well known hole in the TCP/IPv4 protocol simply because he doesn't want people to know about it and upgrade to IPv6. Of course if they did then he wouldn't be able to get consulting jobs by showing the exploit and them having these Fortune 500 companies pay him big bucks to fix them. Here's a freebie to all you from Wagner Consulting LLC., UPGRADE YOUR NETWORK LAYER TO IPv6!!!
Fred Brooks in "The Mythical Man Month" states that for every exploit you find in your code there are 3 that go un-found so this means that there are still lots of holes in IPv4, yet the ack flood is the easiest one to exploit.
Warmest regards,
--Jack
Wagner LLC Consulting Co. - Getting it right the first time
I got the swedish translatin of this book as a christmas gift from my father. Although I find the book somewhat interresting, the translation could be better.
More like:
Chapter 7: Porn Sites and Dangerous Screen Savers
HallmarkOrnaments.Com
it's all nonsense, no DOWt.
we've had sites up for years. although there's been minor vandalism (boyz with billy boXes, no DOWt), all in all, webhosting has been a real pleasure.
the real foolz, are folks who (are MiSled to) bulleave that they can store sensitive inf. (covers a universe of stuff), on public webservers. not yet, you can't.
tell 'em robbIE. you MuSt be leaving a windough open somewhere (over the rainbow) for all those whoreabull corepirate slackhard jump-you ADs, to keep popping up, taking over yOUR hole cite?
One of the anecdotes in this book exploits a SecurID, using a well-meaning 3rd party. Basically a caller poses as an employee when talking to an operator during a snowstorm. He says he needs to get some work done, but he left his SecurID on his desk. The operator doesn't want to go to the desk to get it, so instead he gives his own SecurID number and PIN to the caller. This was probably one of the most clever manipulations in the book.
Fundamentally, any time you have a human involved in a process, you have a potential security hole.
-Alison
Who says geeks don't have good people skills?
teeker
Just ask the idiots who opened the files that someone sent them to ask for advice!!!!! :P
Or the people who listen to me when I tell them they have to reboot hourly to 'swab their ram'.
I swear, people should need to get a license before they can operate a computer.
It's about live coverage of his first Internet surf in 5 years...
enJoy :)
The one I like is RFID on the employee's nametag and a biometric reader (thumbprint in this case) on the terminal.
User walks up, computer detect that Bob Jones is standing there, Bob Jones presses thumb, computer says that this is in fact Bob Jones. Unlock.
The problem is always the human element.... and money too.
....can scale any fortress wall.
Philip of Macedon said that (I seem to remember) 2300 year ago. To put it short more codes have been cracked and more defenses of any kind have been breached by exploiting simple human weakness than any clever hacking/engineering ever has and ever will. It usually is the easyest way. Take the Enigma code, it was cracked, partly, because of the simplistic and repetitive choices of code key words made by the Wehrmacht communications personnel. It never ceases to amaze me how deeply this fact disappoints the tech freaks of this world. If I had to guess all the nerds at CIA-Langley with all their cool equipment will not contribute even half as much to catching Osam Bin Landen or determining his fate as simple traitors within Al Quaeda will do.
Only to idiots, are orders laws.
-- Henning von Tresckow
First, what's in this book? The bulk of the book is given over to scenarios of different types of social engineering attacks. This includes things like acting helpless, offering help and guilting your victim into "owing you something", and pushing certain psychological buttons designed to make the victim feel whatever emotions you want. There's also some stuff about how to create a good security policy for your organization, but you can skip that. There are much better references for this sort of thing.
What did I like? The scenarios sure are entertaining! The book covers a wide variety of different situations and goals, from tricking someone into telling you their password to gaining physical access to "secure" facilities. The authors tell the story of each attack both from the victim's point of view and from the attackers, then provide an analysis of why it worked and how it could have been prevented. Very valuable!
What did I dislike? There's a substantial amount of repetition in the scenarios, but some may view that as useful reinforcment, so it's not necessarily a bad thing. As I said, I think the security policy section isn't very good, and it could easily have been left out.
My overall impression is good, and I highly recommend this to anyone responsible for physical or information security in their organization.
Check out my eclectic infosec blog at InfoSecPotpou
Don Norman's praise,
Rob Slade's review (same issue), and
Don Norman's response to Slade's review
it's really not a bad book, and if I could slashdot a book, I would first slashdot all of my C++ books, then this guy's stupid book. but not before slashdotting all of your houses, and that stupid physics of star trek book.
and stephen king, that arrogant ass
Where do you get that figure of 1.86 Billion dollars from?
When I met Kevin Mitnick, he was just scraping by and is hoping his book sells well so he can get out of debt and pay off restitution. He's also hoping that Defensive Thinking takes off.
I think he sees himself as someone who is being given a second chance, and I think he wants to prove himself to the larger society as someone who is an asset, not a threat or liability.
By the way, Kevin is a nice guy in person, for what that's worth. Probably nicer than I am. He's also a good public speaker and has a few funny stories in him, if you can get him to open up.
I think he deserves to be given a chance to clear the air on some of the more outlandish charges that were leveled against him in the media (and didn't stick in court).
I understand that he'll be able to get on the Internet next week... maybe you can write him and ask him how things went down from his point of view. But he's probably more intersted in his future than in his past.
--No Account Coward
But I've cut off his thumb, let me in...
The one I like is RFID on the employee's nametag and a biometric reader (thumbprint in this case) on the terminal. User walks up, computer detect that Bob Jones is standing there, Bob Jones presses thumb, computer says that this is in fact Bob Jones. Unlock.
That's a pretty good system, although it has a few fundamental flaws that make it unsuitable for ultra-paranoid environments. The problem is that Bob's fingerprint is a static key. If I want to fool the system, all I have to do is to capture Bob's fingerprint. Then I walk up to the computer, unplug the fingerprint reader and substitute my own device which simply reports that I am Bob.
You could improve the fingerprint reader system a bit by encrypting the wire protocol between the hardware and the device driver, but it's still technically feasible to break open the device and splice in the pre-computed signal. Still, admittedly the fingerprint reader is not open to a social engineering attack.
-a
I wondered if the author actually committed the social crime like Frank W. Abagnale? :) who wrote the book The Art of the Steal and
Catch Me If You Can - yes, the movie
:)
(save your mod point elsewhere thanks.
while there is a semi-truth to this report, what actually happened was that he had a heart attack
after i cut his fingers off that peice of crap
I am a bit of an optimist, so obviously my view is coloured.
I think most people want to do whatever they do well. They want to do a good job, be productive and have a positive impact.
Many times the security at a location (Bouncers, Security guards, Police, Military, or receptionist) won't let you pass with a bribe, they want to do a good job.
Although I think it is much more rare that they'd deny you access for something reasonable. I have to use the restroom, forgot my coat, is my gf/wife/friend in there, have you seen Mr Smith, he said he'd meet me.
That is the point, you can get this useful information even if it shouldn't be given out depending on your approach, which is the point that he is trying to convey.
1) Ideally build security around "what you have/what you know" to the greatest extent possible.
;) If the employee gives out their login info, you send them an email letting them know that they should NEVER give out login information to ANYONE for ANY REASON, and tell them to change their password. Explain that passwords are not accessible to anyone, and that login information is available to anyone who would be investigating security problems. If it happens again, send an email to their manager as well ;-)
2) Train, train, train!
3) Just like you do a network security audit from time to time, do mock attacks! Call up an employee and use something like the following script (modified each time)
"Hi, my name is Joe Angstrom. I work over in IT."
"We are investigating a potential security problem on our network and need to ask you a few questions. Have you noticed anything strange about your computer recently?"
"Thank you, this has been very helpful. There is one more thing. So that we can be sure of this, could you verify your username and password?"
Just make sure that it is approved of before you do it
The point is-- human factors can be mitigated by training, but no one puts that effort into things.
LedgerSMB: Open source Accounting/ERP
A HUGE part of my job is preventing social engineering type stuff (or if you want to be specific - evaluating the degree to which a client has successfully implemented good risk management and security management). I interview people all the time, and I assure you that waving $100 is the most sure fire way to not get what you want.
People are more afraid of getting caught, of loosing their job or of getting in trouble than I think you realize. That said, it is amazing the things people do, if they think they're supposed to do them.
I'll routinely call people at a client and just start asking questions to total strangers. I've been in server rooms interviewing people and I'll ask questions like, "How does a visitor get access to this room?" When they answer, I'll ALWAYS follow up with, "Why was I not subjected to that procedure?" I'm legitimately supposed to get access to the information I get, and I sign NDAs and get approval for everything I do. Not once have I ever been challenged to provide that information. (For some reason, if you call the manager of a department and tell him that you'll be talking to his employees and why - they assume you're legitimate.)
Show up, talk the talk and look like you belong there and people will tell you anything. Wave around $100 and people call security.
Even better at Walmart.
I read an article, I think it was in Novell's magazine or whatever they call it. It was about school computers in (I think) Norway and how they were now using a card/password scheme. They did this because there was a big problem with kids giving other kids their passwords (which is a bigger problem there than in the US because all of their schools are on a WAN). I thought it was a pretty good solution.
"You should only bother reading The Art of Deception if you know next to nothing about the human aspect of security and then only if you really think you are safe."
The only book on "The Art of Deception" one should read is this one.
If you want to read this criminal's handbook, read it in the bookstore. (maybe borrow it from bookstore) Maybe read it in the library, DO NOT CHECK IT OUT! Library lists are subject to FBI warrants. Do not pay for it, why give a thief money? Mitnick is a DIRT BAG! I wish I could leave my doors unlocked like in the old west, and just shoot trespassers. Assholes like him, make ME have to lock MY doors.
Affiliate tags aside, according to OCLC's WorldCat about 450 libraries have this book available for lending free of charge. If you library doesn't, you can still usually order it through an interlibrary loan service.
Am I the only participant to this forum who thinks that any admiration on Mitnick is admiration on a crook?
Actually, I haven't really seen too many posts here glorifing Mitnick so I don't know where your incredulous attitude is coming from. I agree that he is not someone to be admired. I'm guessing that a large number of slashdotters do too. However, we are interested in what he has to say, regardless of whether he was a decent person or not. He did manage to pull off quite a few feats. There are a lot of people here saying things like "Oh, that's obvious" and "He has no technical skill." So what? He has shown us that technical skill is really not required. As technical/science/engineering types here, we are interested in discovering the truth -- even if the truth is underwhelming when we finally get to it.
I.e. Mr. Mitnick is a criminal, who may or may not have extraordinary technological savvy; all those years in jail, and post-jail constraints, were surely well-deserved.
True enough. But there is something to be learned from his book (I'm guessing here -- I haven't read it). That's why the review is here on slashdot. That, in an of itself, doesn't imply that we're all Mitnick fanboys around here.
GMD
watch this
Didn't they get around this in "Ocean's 11" by tricking the guard with the scrambling password to take their package in for them? I'm thinking of the scene where the two twins get the guard to take the cart with the little Chinese guy inside into the vault--
for high security applications.
It even has self-destruct circtury built in.
Check it out.
Kevin Mitnick, the can't leave other people's stuff alone, trespassing son of a bitch, would have been hanged by the neck until he was dead, his supporters would have been hung along side him.
But instead this asshole writes a book. Watch your step Kevin, aiding and abetting criminal activities will get you back in jail forever.
You could always just take Bob's thumb. You could also find out some piece of information about Bob that could be used to make Bob want to let you in. You could drug Bob. You or someone working for you could seduce Bob. You could offer Bob a large amount of money/pr0n/whateverelseBobwants. You could convince Bob that you are good and that the person running the system you want access to is evil and that Bob should let you in.
Do not fool yourself *anytime* there is a human involved you can use social engineering to get in.
Cypherpunks: Civil Liberty Through Complex Mathematics. Those who live by the sword die by the arrow.
It is just a new buzz word for Flim Flam man, Con artist and criminal in general. Not a real skill. Just what politicians ans niggers do each day!
To prevent cracking security in human beings. At least until God releases a patch.
"The Sage treasures Unity and measures all things by it" - Lao Tzu
he proved to me how skilled he is at social engineering when he used it to get me to buy it. At my bookstore he gave away a small chapter sample of the book, but it was enough that after reading it I had to purchase the rest of the book...
He's a sneaky guy, this Kevin.
~ kjrose
...Is that the corporate big-wigs hit Mitnick with DMCA. After all, corporate espionage is the process of stealing information.
There's a line that needs to be pointed out: The differences between proprietary information, copyrighted materials, and trade secrets.
Both copyrights and trade secrets contribute to proprietary information. The only sense behind the DMCA is that it's supposed protects proprietary information. I don't think that the legislators realized that's what the spirit of the law really is.
I'm hoping some large company, like a biotech firm, turns around and tries to slam Mitnick, because this book can be considered controversial enough to warrant an extended legal battle.
The defense would have to point out that writing books has long been considered part of free speech, and that one consequence of this law is to suppress that speech when it goes against the wishes of corporations with massive volumes of sensitive data.
The prosecution would then have to point out that copyrights are a specific exemption to the first ammendment. They'd probably try to point out that copyrights and proprietary information are in the same boat; their goal is not to be shared. Enter retroactive copyright legality.
It's a pipe dream, and I'm probably all washed up, but here's to hoping.
Consequences would follow, though. Mitnick is going to need money for lawyers. Where's he going to get it? For this topic, I'm sure a lot of people of geek origin would donate some money. In any case, the spin placed on the court case by the prosecuting company is goint to paint the book as "a tool for hackers, by a hacker." (Note the quotes.)
Any lawyer who defends him, and everyone who sends support, is going to be guilty by association with a cracker. That means the open-source and free-software crowds. (Indeed, we'd only have to provide verbal support in order for companies like Microsoft and the **AAs to paint open source as an evil underground movement.
What's this Submit thingy do?
Known Troll! (Hint: just because you don't know what he is talking about, dosen't mean he is smarter than you.)
There were recently 2 reviews of this book on the Risks mailing list: a positive one, a not so poitive one, and a reply to the not-so-positive one.
When you hear about some poor security guy that hands out his name/password to a fake employee, or a end-user that wilfully installs back-door software onto their machine you generally think 'I hope they can find a new job.' The biggest surprise to me is that very often people who violate these basic security principles are NOT held accountable for what they do.
During my time at one of the nations larger companies I witnessed several different instances of employees serving as giant security holes. It was a big problem for the company. Instead of training and then actually holding employees accountable for their actions, more often than not the employees simply went on after the incident so they could do it again later.
Companies need to invest time and money in training employees (EVERY employee with access to sensitive systems) and then developing systems by which employees can be held accountable for any security holes they create.
Turn s60 photos into awesome videos with mScrapbook for all S60 3rd edition phones!
"There was one chapter in particular that reallystood out for me. This was the one where Mitnick told HIS side of the story - of the despair and frustration of being demonized in the media and locked away for five years. He told of his anger towards John Markoff, the New York Times reporter who wrote articles about Mitnick that seemed to demonize him and who later went on to write a book which turned into a movie - all while Mitnick languished in jail. I think in a way it was therapeutic for Mitnick to get his anger out at last and certainly about time that the public got to hear his words.
But these are words you WONT be hearing. Markoff's lawyers send the book publishers a threatening letter that was about as long as the chapter itself and Wiley is no longer printing that part of the book.(They claim to have reached this decision independantly)."
----Review done by Emmanuel Goldstein
Yes, I've always seen a parallel between Mitnick and Abagnale. My grandfather helped bring in Abagnale, and when I talked to him a few years ago about Mitnick, he said he felt some deja vu coming on. This is how it will always be, I think that's the point of social engineering -- there will always be a way around the system.
This is my digital signature. 10011011001
I wonder how may of the anti Mitnick post are from Markoff and Shimomura. Haven't you kick him around enough?
world was created 5 seconds before this post as it is.
The book is interesting to read, but most of the stories are fictional. In general, it can give you a better understanding of the concepts and possibilities of social engineering, so you can learn to protect yourself. Mostly, I think it will serve as entertainment, especially for the anti-social engineers :).
I did get the impression that not all of the fictional stories were completely made up... and the book takes a little off of the rosy sheen a lot of the "hacker community" tries to put on social engineering and Kevin's actions (but hey, if you take anything the media or the "hacker community" says at face value you're living in a dream world). Now before I get flames, I'm not advocating illegal imprisonment, I'm just saying the term "innocent hackers" is a little too often used. To his credit, I don't think Mitnick claims to be innocent.
MasterSLATE is the Slashdot pseudonym of William Shatner.
Sorry that my post got so long.
Always keep a sapphire in your mind
The Washington Post had an online chat with Mitnick a month or two back.
;-) )
;-). Or maybe he could use his court-approved laptop. ;-)
(Bitterness continues long after submission!
Interesting read, but I really enjoyed this part:
"Per the terms of his parole agreement, Mitnick is barred from using nearly all computers except a court-approved laptop. He is also prohibited from sending e-mail or surfing the Internet. As such, Mitnick dictated his responses to a washingtonpost.com staffer who transcribed."
That said, I wonder, was this the last book every written without a computer?
So close and yet so far from the world's perfect ID number
They stuck it to him now he's sticking it to them with a book on how to be a digital grifter.
Revenge is sweet.
It's Christmas everyday with BitTorrent.
I was wondering if everyone reading this could give thier credit card number. I need to buy some office supplies for your company. It would be greatly appreciated.
Email me at gtowne@fishertowne.com
Some other examples of social engineering are found in Catch Me If You Can. A very enjoyable movie about the exploits of Frank Abagnale Jr. I just saw it the other day and really liked it. DiCaprio did a really good job in this. I guess the guy can act after all. :-)
-- This is not a sig
since when is summarizing the table of contents a review?
Everyone (with an IMDB account at least) head to http://us.imdb.com/Title?0159784 and rate the movie "Takedown" a 1. Show people you are tired of bogus reporting of technology stories.
You think this is a joke, but that's what the last place I worked for did. They thought of it as "personal responsibility". No training, nothing useful. They ran M$ for everything server to desktop, then made it so they could blame someone when things were broken into, complete with an electronic signature. What else do you expect from a M$ shop? You "training" efforts there would just end up as another way to "renew" or fire people.
Friends don't help friends install M$ junk.
What Mitnick really should have done was write a book that showed the geeks of the world how to use social engineering to get laid. Now we're talking best seller.
I hope I'm not the only one out there who gets disgusted everytime I here the term "social engineering" used to describe what is essentially taking advantage of individuals who are only guilty of being naive and trusting. I've spent my entire adult life around engineers, and almost without exception, the one thing they all had in common was that they work hard to create something new and useful for the benefit of others. The coining of the term "social engieering" to describe the under-handed techniques used to get people to betray the security of their system is, to me, an afront to engineers everywhere. I have no idea what thought process lead Mr. Mitnick to describe what is essentially a con artist as some sort of engineer. In my mind, an engineer is someone you can trust and can rely on to get a job done. The key words being trust and rely upon.
Mr. Mitnick, if you are reading this, I would ask that you please reconsider popularlizing the term "social engineering" to describe what you did. I'd much rather the term engineer continue to be synonomous with helpful and useful rather than deceitful and untrustworthy.
(For a better example of what I would consider social engineering, please refer to _Childhood's End_ by Arthur C. Clarke.)
What if Bob has no thumb?
Exempli gratia: "What's Eating Gilbert Grape" and "The Basketball Diaries." Just because he was atrocious in "Titanic" and was a teen idol for a while doesn't mean he's useless. Look at what happened to Johnny Depp! He was a teen idol with a popular TV show, and then he started taking quirky roles in movies like "Ed Wood." He's one of the best actors in the business now, and one with an incredible ability to become the characters he portrays. DiCaprio is turning out to be the New Millenium answer to Johnny Depp.
A collegue used to regail me (frequently) with a story about Dr Alan Solomon attending a security device demonstration. The organisers demonstrated their device, claiming that the chip would prevent unauthorised access.
Dr Solomon asked permission to view the device. Before anyone could stop him, he pulled a large screwdriver from his pocket, jimmied open the case, and popped the chip from its socket. In less than a minute, he'd circumvented a complex device using BFI (Brute force and ignorance). Thereafter he was able to access the data the chip supposedly protected.
The demonstrators were aghast, but the lesson was clear. It's possible to bypass complex security using simple tools, especially if you don't mind breaking things.
Environmentalism is the new Victorianism. Everyone ties on a green corset and pretends we're virtuous.
Last time I was in the Microcenter store in Atlanta (the one on Powers Ferry Road), they had several copies of this book on sale for $5.
Sometimes I worry that I'll develop Alzheimer's disease, but no one will notice.
While the focus amongst technocrats is often the technology companies, or the main tech areas of non-tech based companies this misses the majority of the issues out there.
I am still not established enough of a geek to be established in a tech job, instead I stock shelves at the local large grocery store. Recently, without even seeking it, I was granted access to the pricing computer by a fellow employee who was trying to be helpfull. I needed the prices on many items checked and he didn't want to do it. The interesting thing is that he didn't have offical access to that computer either, he only new the access code from another location- they both happened to have the same access code.
At this point you may be saying, so what? Well the store in question has many locations, all of which likely use the same information to access the computers. If I wanted I could go into the pricing computer and change the the information for any product in the store, buy as much as I wanted, and change it back.
This is a company that has signs on the door of its server room that say "Treat anyone requesting access to this room the same way you would anyone requesting access to the cash office." But when it comes to computers, people need to remember that physical access is not necessaty.
Now I am faced with a dillema. I am not, by any means going to abuse this information. In fact, it allows me to be a more effective employee in some regards. It does, however, mean that they need to evaluate thier security. Do I tell them, knowing that that this might get myself and my co-worker in trouble. Do I wait for it to become an issue before informing them? I imagine I shall send an anonymous note to the central office in the end, listing certain recommendations.
This goes to show that corporations like to be able to move people from location to location without much change, so they skimp on security. Hacks on technical systems can often be run from low level accounts, information given out is not always intentionaly sought or given. Every corporation needs clear, easy to understand rules that explain to their employees why they are there, and they need to train everyone to be security conscious- not just those who run the show.
I thought that in the united states convicted criminals weren't allowed to profit off of their crimes? Can someone please explain how Mitnick is allowed to write a book like this and receive profits. Thanks
I strongly second this post!
I'm studying for a CISSP cert and have found Secrets and Lies to be informative and inspiring.
Bah!
OhmyGod,youareright!y pingaspace!
NowonderIhavesomuchtroublet
Thanks,Bob
He couldn't use technology! This book is a triumph considering the constrictions that Kevin was under and I was happy to have bought it. I can't remember the last time I bought a hard cover.
Anyways, OF COURSE it's NOT about hacking. He hasn't had the chance to hack anything in years. He couldn't use the internet until last week for Jiminey Crickets! Not to mention that the NAME OF THE BOOK is "The Art of Deception". Everyone who thought Kevin was going to deceive some buffers into overflowing with this book should be round up and shot with nerf munitions.
Anyways, I'M enjoying it. If you causually follow the hacker scene you'll be happy with the first couple chapters. I'm in the middle of reading it now. Njoy.
feints within feints, wheels within wheels
anyone got it? Is it Markoff@nyt.com ?
I couldn't register that one, it was taken.
If I was Mitnick, I would spend the rest of my life making things sh**ty for this guy.
You could always just take Bob's thumb. You could also find out some piece of information about Bob that could be used to make Bob want to let you in. You could drug Bob. You or someone working for you could seduce Bob. You could offer Bob a large amount of money/pr0n/whateverelseBobwants. You could convince Bob that you are good and that the person running the system you want access to is evil and that Bob should let you in.
Do not fool yourself *anytime* there is a human involved you can use social engineering to get in.
I never said that the system was perfect, I just said that it was basically immune to social engineering. The attacks you describe seem more akin to corporate espionage (with the exception of cutting off the thumb, which is assault). I don't know if there is a definative definition of "social engineering", but I did a quick Google search and the definitions I found did not appear to include corporate espionage or violence.
-a
I've got to respond to several things I've read here...First of all I would have thought the editors would hold out for a real review of the book by the famous/infamous Kevin Mitnick!
With that said, many people are saying they are 'surprised' by the fact that this book doesn't emphasize technical aspects of hacking. Have you heard nothing of this book?! It says right on the cover that this is a book about social engineering, and much of Kevin's fame was due not to his technical prowess, but the combination of tech and 'social engineering'.
With that said, I believe Kevin is a very intelligent person. I have heard him speak, and he is very well spoken, and organized. It is no wonder he was so successful at manipulating people in order to gain information he sought. I have to say that, although it takes an intelligent person to do this, I can't help thinking that 'social engineer' is only one way to interpret a malicious liar. Especially since he admittedly did most of his hacking 'for fun!'. When James Bond does it, its admirable, as it usually saves the world. In Kevin's case, he did it for the thrill of it (a hallmark of true hackers) and to see if he could get away with it. Something pathalogical about that...(although I don't doubt his self-proclaimed reform from 'the life' and new interest in helping people avoid being exploited by people like himself...)
Some people are also saying here that they believe he is a criminal, and deserved to be in jail. Kevin himself doesn't deny that he broke the law, but the reason the hacker community rallied around his cause is that he was denied a bail hearing for years, denied many of his legal rights, and generally kept in legal limbo (and thus in jail) for many years. This, despite the fact that his actual crimes were pretty insignificant (although obviously punishable). This is pre 9/11, and he was basically intentionally 'lost in the system' and denied his rights because people in power feared him, and what they assumed he was capable of.
Read the first chapter of the book, linked somewhere above, and also check out "Freedom Downtime", the documentary done by 2600.
What? Engineers are social?
Because even well-meaning people are not capable of being completely responsible for these abuses if they are not properly trained or aware of how these things occur.
No one is responsible for what other people do without their knowldge and consent. Blaming the user for network security and software bugs is sorry. Telling people not to share their passwords and using that as a means of transfering blame is a cop-out. There should not be a way for someone to get at company information simply by talking to an employee over the phone or through email sniffing. Information that should be gaurded needs to be gaurded and employees who use the tools their employers give them are not responsible when those tools fail them. That's why I was disgusted with the way things were actually done.
Your test is a bad idea. It is predicated on responsibility that should not be born by the employee. The very fact that the test might be useful shows that there are huge holes in data security. A company that displaces blame like that will invariably use your test data to fire competent employees when things get tight.
Friends don't help friends install M$ junk.
I'm currently in the middle of this book, so consider this as a half review.
First note: Kevin Mitnick didn't WRITE it, he contributed.. "co-authored".
Second note: It's a text-book format. And they did a very poor job with it too. The "Mitnick-Messages" and "Lingos" and the rest are frequently positioned in the middle of sentences, which I find illogical and poorly organized. They are also frequently redundant.
Third Note: This book is for people and companies wanting to protect against social engineers. If you're looking to become a social engineer, you'll find little useful information in this book.
The Introduction, Preface, and First Chapter are all the same; pick one and skip the other two. I swear if they said "humans are the weakest factor" one more time I was going to throw the book out the window. These sections were very poorly written and painful to read, but don't worry, it gets better.
The middle chapters are filled with fictional stories meant to illustrate methods and scenarios used by social engineers. Personally I find them to be rather vague on details. Of course, you couldn't expect a book to illustrate every conceivable scenario. The authors then try to analyze the situation, and offer suggestions on how to circumvent the attackers.
If your business deals with sensitive or private information, this book will probably make you lie awake at night in a cold sweat, afraid to turn on your computer. You'll trust noone. You will force your employees to destroy their phones and communicate via telegraph and Western Union telegrams. Your business will inevitably be overcome with social engineers exploiting your every weakness and pilfering your every assest.
I wouldn't recommend this book (so far) for anyone except security professionals, or perhaps business owners who have been burned in the past. Script kiddies, wanna be hax0rs, and other CriMiNalz will get nothing out of this book. You can't learn confidence and assertiveness from a book.
it can't really teach social engineering. it's like acting or writing or any other talent: it's innate. we can all pick up a trick or two here and there, but it's not going to turn a Baldwin into a DeNiro, if you know what I mean.
This man is the expert in deceoption.
Security is a total solution, and it involves people, administration, software, etc.
I think that where we agree is that security needs to be a systemic effort on the part of the employer, but I think we disagree on what needs to be part of the system. And I think you are right that some companies will use this to fire competent employees when things get tight. But my pov is that such companies will fire such competent employees anyway, and that is an HR problem, not a security problem.
However, I think that from a raw security viewpoint, one has to always bear in mind that the weakest link is the critical one and if you assume that you don't need to worry about your employees, then you have to conclude that you cannot trust them at all. You could then do things like have security guards search everyone as they enter or leave (like some companies have done), but one way or another, you end up in this area.
I guess the fundamental principle is that employees should be mindful of their employers too.
LedgerSMB: Open source Accounting/ERP
ignore this.
I love the song (you know which one;) Mr. Mitnik....you're my hero and role model =D I'm going to be like you when i grow up lol...well that's kinda soon... One thing though, you could be a little more eh sociable in person don't hug the conversation all to yourself...ah well what can one expect from a genius. I've always thought to myself that one should empower the end user. Sometimes it's depressing the things that corporations get away with. It's like there's an entire generation of mass produced computers out there that tease the user with the flare of media presentations that pass as desirable sofware. Ah well back to my studies or I'll never catch up with the standards of life...and heaven forbid programable languages. *cheers to journey* =D
Don't hesitate
sw33t ...Walmart is making stores go out of business because they have such good prices in my area
Don't hesitate