Slashdot Mirror


Mitnick: Security Not about Technology

renai42 writes "Companies eager to tighten up their information security perimeters should focus not on technology but on teaching their employees how to say 'no', ex-hacker done good Kevin Mitnick told a full house at Toshiba's MobileXchange conference in Melbourne yesterday. 'We can't expect our employees to be human lie detectors,' Mitnick said. 'One of the most difficult challenges in corporate cultures is getting people to modify their politeness norms.'"

90 of 387 comments (clear)

  1. As Nancy Reagan would put it... by carninja · · Score: 5, Funny

    Just say NO!

  2. FREE KEVIN! by Anonymous Coward · · Score: 5, Funny

    oh wait..nevermind..its 2005

    1. Re:FREE KEVIN! by Wolfgame · · Score: 2, Funny

      Get yours while supplies last!

      Sorry, that one still makes me giggle.

      --
      -- My childhood bathtoys were Toaster and Hairdryer
  3. How is this news? by Anonymous Coward · · Score: 4, Interesting

    Isn't this what (ex)hackers have been telling the IT industry all along?

    1. Re:How is this news? by rjordan · · Score: 3, Insightful

      More specifically this is what Mitnick has been telling people all along - I seem to read about him saying this regularly....

      --
      "When no-one around you understands start your own revolution and cut out the middle man"
    2. Re:How is this news? by digitalchinky · · Score: 4, Interesting

      When working as sys-admin I clearly tell people 'Do NOT give ME your password, I don't need it to do my job' - Ten seconds later - Now log in for me, 12 seconds later, my password is 'fluffy'...

      People are dumb until it's too late, not all, but enough to make the stereotype hold true anyway.

    3. Re:How is this news? by MillionthMonkey · · Score: 3, Insightful

      Isn't this what (ex)hackers have been telling the IT industry all along?

      As old hackers while away the years (in jail) the industry moves on, which means their skills become dated and they lose all their technical expertise that got them in so much trouble in the first place. So they move on to pretending that all you need to do is act nice and con the receptionist or some fool on the other end of a phone. That route of attack is not as affected by one's weathering technical skills.

      Ring ring
      Hello, this is Bill.
      Bill, hi, this is "Steve". I'm stuck outside the building- this stupid thing won't let me in. Could you read me our private key real quick?
      OK, it's A244C7735ABBFC01... hey, how do I know you're really Steve!

    4. Re:How is this news? by Anonymous Coward · · Score: 5, Insightful

      I don't really believe that most people are dumb. Most people just want to do their job, whatever it is, and they think that it is up to YOU to prevent people from "hacking the system." In their mind if something goes wrong, it's YOUR fault.

      The biggest problem is that people's views are flawed, they need to be told WHY they shouldn't give their passwords out. Rather than saying, "I won't ever ask for your password, don't give it out," say something like, "there are these people who use social engineering..." etc...

      Will this prevent social engineering attacks? No, but it WILL help to prevent them. People won't do what they are told if they don't know why they shouldn't do it, regardless of the profession (is that enough double negatives?)

      But what do I know, I'm just Anonymous Coward.

    5. Re:How is this news? by godless+dave · · Score: 3, Insightful

      It's news because (most of) the industry still isn't listening.

      --
      "If it's real, then it gets more interesting the closer you examine it. If it's not real, just the opposite is true." -
    6. Re:How is this news? by Errtu76 · · Score: 2, Interesting

      I remember when i worked at a university, there was some intern (sent out by the IT guys) going by every department, asking people to give up their passwords. This was because of some inventory/migration/bullshit-excuse. I kid you not. I refused to give my password to anyone, saying that if i had to give it up to anyone other than the login screen, it was worthless. What was weird about it, was that apparently i was one of the few who refused to give it. Most people had no problem handing over their 'secret' and 'highly personal' data, just because somebody asked for it...

    7. Re:How is this news? by MillionthMonkey · · Score: 2, Insightful

      Yes, it's skewed and oversimplified. I needed to set up my subtle joke about Bill Gates and Steve Ballmer. Too subtle unfortunately.

      But even if you're the guy who the cops thought could launch cruise missiles by whistling into a phone, it's hard enough to stay on top of all this crap when you're, say, not forbidden by a judge to go near a computer for several years. And he got into trouble in the first place at least partly by social engineering. Which is an area of computer security that nobody thinks about- an obvious, accessible market for someone like him. So it isn't surprising that he's taking that approach. I'd do it too if I were in his situation.

    8. Re:How is this news? by Linker3000 · · Score: 5, Interesting

      In my previous job I worked as a trainer and consultant for many blue chip companies and spent a lot of time in their corporate HQs, Call Centres and Help Desks.

      Invariably, front desk security was adequate, but it was easy to get into many Call Centres and Help Desks without a key card, fob or access code simply by waiting for an employee to walk towards the main door and then approaching the same door carrying an abviously heavy, large box full of training manuals - most people in service delivery roles want to be helpful so they often hold the door open for you! In 6 years of consulting I was only ever challenged once.

      In reverse, I would occasionally be coming out of a building and someone would ask me to hold the door because they had forgotten their pass - it would really piss them off when refused to let them in and said if they waited outside I would fetch a team leader or manager for them!

      --
      AT&ROFLMAO
    9. Re:How is this news? by bampot · · Score: 3, Interesting

      It is against Company Policy here (very large multi-national company) to divulge your password, even if for critical busines issues. Employees are expected to log a call with the service desk for a reset. Working in the middle of the night on a critical project? Tough - you should have arranged on-call support.

      Divulging a password is a disciplinary offence too, but it still happens regulary - mostly because it's rarely enforced.

      Here are some random office rules that are obeyed without question, these are all disciplinary offences, and are regularly enforced:

      * always hold the handrail on the stairs
      * do not walk AND talk on the phone/read bits of paper
      * hot drinks MUST have lids on
      * etc.

      People follow these rules without question (I don't), but I think the average perception is that it's harmless to give out a password.

      Unless there very real personal consequence of divulging passwords etc., it's always going to happen.

    10. Re:How is this news? by markov_chain · · Score: 2, Insightful

      I'm getting tired of all the complaining about passwords and their insecurity. It is hard to change people, and if you don't want them to give away password information, don't give them any. If we can use keys to get into our homes we should be able to use them for authentication as well.

      --
      Tsunami -- You can't bring a good wave down!
    11. Re:How is this news? by Errtu76 · · Score: 2, Insightful

      and if you don't want them to give away password information, don't give them any

      Sorry, but that isn't a good solution. In certain cases users have to have a password. We have to teach the users the consequences of giving away their password, and teach them some responsibility. What i always say is: If you give your password to somebody and that somebody uses it for less-than-legal purposes, it will be *your* responsibility. No excuses, no investigation and no second chances. Want to be safe? Don't give away your password, period.

    12. Re:How is this news? by Lumpy · · Score: 2, Interesting

      I don't really believe that most people are dumb.

      Wow! you must be a youngster.

      The average IQ here in the United States is below 100 (around 97 I recall)

      That means on average everyone around you is only 17 tiny points away from being a clinical moron. A good strike to the head can get them there in a hurry.

      I have people that we have had to LOCK DOWN their computer completely with TrustNoEXE because they can not understand what it means when we say "DO NOT DOWNLOAD AND INSTALL ANYTHING". Somehow they interpet that as "Please install Webshots, Elf bowling, yahoo Toolbar and oh that cute free time keeper app! we LOVE it when you install that cutsey stuff."

      If that is not a sign of stupidity, then I have no idea what is....

      But then a bulk of my users are Marketing and Sales, so I wonder if the average IQ here is far lower than the norm.

      --
      Do not look at laser with remaining good eye.
    13. Re:How is this news? by Hognoxious · · Score: 3, Funny

      Simple, don't tell the (l)users their passwords in the first place. Do I have to do all the thinking round here?

      --
      Confucius say, "Find worm in apple - bad. Find half a worm - worse."
    14. Re:How is this news? by Anonymous Coward · · Score: 2, Funny

      12 seconds later, my password is 'fluffy'...
      Geez, I said I was sorry! You didn't have to give everyone my password.

    15. Re:How is this news? by Some+Dumbass... · · Score: 2, Funny

      Isn't this what (ex)hackers have been telling the IT industry all along?

      Yeah, but for some reason nobody ever believes them, and I think I know why.

      boss: "So, you're a computer geek hacker-type, eh?"

      ex-hacker: "Yes."

      boss: "And what you want to teach us is..."

      ex-hacker: "How to relate to people."

      boss: *laugh* *chortle* *door slam in face*

    16. Re:How is this news? by Techguy666 · · Score: 2, Interesting

      I work in a school so the security needs aren't as severe, but when a student's own laptop is completely bogged down in viruses and spyware, cleaning Windows XP actually goes a lot faster when you have the student's password. Spyware tends to cling to a profile and unless you're running that profile, it's difficult to see whether you've been successful.

      I suppose we can re-image a machine that's been infected but students become severely traumatized when they lose work, programs, and the iTunes they've collected. On the other hand, I'm contributing to entire generations of people who would rather trade their passwords than lose their music collection. I don't know which makes me feel more guilty.

    17. Re:How is this news? by bluGill · · Score: 2, Informative

      An IQ of 100 is average.

      An IQ test is very reliable in that you will always get close to the same score. However it is worthless because nobody really knows what any particular score means. You can say your IQ is X, but that gives no insight to anything about you.

    18. Re:How is this news? by SlayerofGods · · Score: 2, Funny

      Ohhh so your the jack ass that made me wait out in the rain when I forgot my badge.
      Your on my list now buddy!

      --

      Technology, the cause of and solution to all of life's problems.
    19. Re:How is this news? by BobNET · · Score: 2, Funny

      And a paperclip named Clippy can't make a document, but it WILL help make one.

  4. Sure we can... by Anonymous Coward · · Score: 5, Interesting

    'We can't expect our employees to be human lie detectors,' Mitnick said.

    Sure we can: http://content.monster.com/martynemko/articles/arc hive/lying/
    1. Re:Sure we can... by jspoon · · Score: 3, Interesting

      That's an article that reads like an explanation of why most social engineering is done over the phone.

    2. Re:Sure we can... by Anonymous Coward · · Score: 2, Interesting

      Good anti-lying-detection article for social engineers.

      On another note, it seems that the easiest way to learn to lie is just to subscribe to relitavism. Being able to believe, honestly, that reality is merely the subjective interpretation of the human mind allows one to effectively emulate other realities in one's own mind while speaking, easing the body language. Essentially, you just have to be able to put your conscious mind into the altered reality state while maintaining enough subconscious realization of the act to keep from believing it yourself. Or just believe it yourself. Religious fanaticism certainly has strong adherants who in their own mind certainly never lie.

  5. pots and kettles by Jippy+T+Flounder · · Score: 5, Funny

    and in other news... "reformed serial rapist teaches women to 'just say no'"

    --
    ---- I was woken up this morning by a face full of fur. Damn cat thought my head made a good pillow.
  6. Computer Security, The Ultimate Oxymoron by Toloran · · Score: 3, Interesting

    I do tech support at my school. My self and two guys finnally finished our new mobile computer lab. Laptops with WiFi cards installed. It makes me sad to think after we get the things nice, clean, working, etc that the idiots will have the things broken beyond recognition by the end of next week. ;_;

    The ultimate security leak, people. >_

    --
    Speaking is NOT communication
  7. Please... by jpiggot · · Score: 4, Insightful
    "politeness norms" my ass...

    What employees need to do is follow the very simple instructions they're given. Change your password regularly. Don't make it obvious. Log out of the system when you're done. Don't use the same password at every site you visit. Etc...

    It's simple, Private Pile...if you lock up that jelly doughnut in your footlocker, it's going to make it very hard for people to steal it.

    1. Re:Please... by stuffisgood · · Score: 2, Informative

      I think what the article is saying is more about social engineering. If companies can teach employees not to fall for social engineering tactics then they can move onto easier to fix things like regularly changed passwords etc.

    2. Re:Please... by tji · · Score: 4, Insightful

      > Change your password regularly. Don't make it obvious. Log out of the system when you're done

      That's fine for making general users more secure..

      What he's talking about is more to do with making admin types more skeptical / less polite. The common 'exploits' that Mitnick, and many others, have done is to learn enough about a target company's practices, and talk your way into getting privileges that employees get.

      e.g. call the phone company's internal support line, talk the talk of the phone technician, and get them to change your account, give you information, etc.

      Or, call a corporate support line complaining of problems with your dialup access to the corporate network. Get them to reset "your" password for you, and you're in the network. 99% of the calls they get are legitimate employees, probably with the same old problems. If you sound like one of those normal employees, the support people will work hard to get you access to the network.

    3. Re:Please... by jpiggot · · Score: 2, Interesting
      I get that...but what I'm saying is that the article doesn't address the larger point, which is that teaching employees to do the simple things can probablly prevent 90% of the problems in the first place.

      THEN, you can fix "social engineering"

    4. Re:Please... by Anonymous Coward · · Score: 5, Informative

      Good grief, changing your password regularly and make it non obvious... this is just such an outdated view that it's almost comical.

      Two immediate issues - sure, the employees computer comes up every 'X' number of days and forces a password change. Most employees alternate between "password A" and "password B" with the only difference being one different letter or number.

      Second issue, the password is forced to be some 8 character password that conforms to a complexity rule that requires letters and numbers, a mix of upper and lower case, and sometimes some non-letter/number characters. These conforming passwords are ones that very few, if any employees can remember so they do what? Write it on a post-it note and stick it on the monitor, under the keyboard, in a drawer, between the pages of the intercompany printed phone book or employee manual or some other 'safe' place that could be determined by an unauthorized person. How do these contribute to increased security??

      Better to break those "politeness norms". You see someone you don't recognize involve them in a conversation. Introduce yourself, ask them about themselves, what they do, who their supervisor is. It's not confrontational, it's non-threatening, and if the person does not seem genuine the questioning employee can make a report to building security with a description. Stop tail-gating at controlled entrances, keep an eye out for co-workers who may forget or seem to be having problems. Respond to unusal requests from outside people by telling the caller you don't have the information handy but can call them back with it within a short time. It also gives time to check with others if the sharing of information is unclear. ALWAYS call back however even if it is to tell the caller that the information cannot be relased. These subtle changes as well as others should foster a culture of security that becomes so second nature to every legitimate employee that the "simple rules" and the threats that accompany non-compliance are no longer the focus.

      I've been promoting and exposing these concepts as an admin and IT Manager since at least the mid 90's.

    5. Re:Please... by Tiamat · · Score: 3, Insightful
      We all know that you can 1) force users to change their passwords regularly, or 2) make your password very difficult to guess. Because people tend to remember very few difficult passwords, to require 1) and 2) means that your users are putting post-its on their monitors to remind them (worse than almost-nothing).

      So, forget 1), and make sure that the first pw someone picks is almost impossible to guess, and let them keep it.

    6. Re:Please... by FireFury03 · · Score: 5, Insightful

      Change your password regularly.

      No, most security experts will tell you this is a very stupid thing to require people to do. Your password system should enforce strong passwords anyway. Enforcing strong passwords which have to change every month just encourages people to write them on a post-it and stick it to their monitor because no one can remember passwords that change that regularly unless they're really simple.

      What's more, it doesn't actually do much for the security anyway: if someone hands random people their password then you're pretty much screwed anyway - people aren't going to wait until after the password change to try and use that password. If someone is brute-forcing passwords then they stand the same mathematical chance of hitting the new password as they did with the old password so no more security there. Infact, the only security it gives you is if someone steals your encrypted password file and it's going to take them a few months to crack. But if random people can get the password database then you've got bigger security concerns than weak passwords.

    7. Re:Please... by pedestrian+crossing · · Score: 3, Insightful

      Change your password regularly.

      ...

      What's more, it doesn't actually do much for the security anyway: if someone hands random people their password then you're pretty much screwed anyway - people aren't going to wait until after the password change to try and use that password.

      Periodic password changes help limit the window of exploitation.

      That's not to say that you aren't royally screwed in some situations (ie., root password/privelige escalation), but in other situations it can really help limit the damage. You don't ever really know if someone else has your password.

      Password changes exploit the fact that it often takes time to leverage a compromised password into useful exploitation.

      Yes, the users are the primary problem (the point of TFA!).

      It's all about using layered defense to incrementally raise the bar of entry.

      --
      A house divided against itself cannot stand.
  8. Con-man gains fame at others expense... by Che+Guevarra · · Score: 3, Interesting

    I'm so sick of this guy's so-called "hacker" fame. He tricked a bunch of early tech no-nothings into telling him their passwords and protocols and now he's living off it forever. Jobs and Woz hacked the phone system, but then they went on to produce something. What has this guy actually ever produced, written, made? Seriously, I don't know and maybe that's a problem. He must have produced something valuable, but I don't know what it is. I'm sure some Slashdot guy will tell me, but isn't it funny that no novice (like me) knows what the hell he's ever done creatively/intellectually in his life?

    1. Re:Con-man gains fame at others expense... by vhold · · Score: 5, Insightful

      What's particularly ironic is that his success mostly stems from getting caught. Had he not failed at the thing he is such an expert on, he'd never have been considered an expert.

    2. Re:Con-man gains fame at others expense... by trs9000 · · Score: 2, Insightful

      Uh? What? My uid is lower than that, I know pretty much nil about security and don't follow Mr. Mitnick's post-hacking career. I just happen to have geeky tendencies and stumbled across the site awhile ago and then registered.
      My point is: don't make assumptions, especially ones based on things as silly as a /. uid #!

    3. Re:Con-man gains fame at others expense... by Anonymous Coward · · Score: 5, Informative


      You should do a little research grashopper. E.g. Mitnick demonstrated that sequence number attacks were possible with TCP/IP. NOT a small thing.

    4. Re:Con-man gains fame at others expense... by Candiri · · Score: 5, Interesting

      You should read up on the guy. His talent lay more with the social engineering aspect of security. He could talk his way into or out of just about anything. His book on social engineering is a good read, McPaper-sized examples, but still very eye-opening. I'm a network admin, 18 years running, and I wound up with a large security laundry list to discuss with my boss the following Monday.

      The other thing is his *years* of jail time were spent before he was ever convicted, i.e. pleaded guilty to some of the charges to cut short his lack-of-a-speedy trial. He's done his time. He can talk as long as people will pay him.

      Besides, ignorance is not unexpected. Many novices probably couldn't tell you who Philo Farnsworth was, even though they've been looking at his invention all their lives.

    5. Re:Con-man gains fame at others expense... by Skuld-Chan · · Score: 3, Insightful

      Have you read his book? If you have you've discounted a lot of the threat of social engineering. Not only do you have to call someone from an external phone network, but in many cases have to know enough to convince anyone from a secretary, white collar worker or IT professional/system administrator to do your bidding.

      I don't think you give social engineers enough credit - because they have to have the ability to pass off as someone who knows more than you do about your own systems and from what I've read he suceeded rather well at this - not only did he convince people to do what he wanted, but he had enough knowhow to do something with that info. And it does take some knowhow - after all once you gain access to a server, telephone switch, network etc - you have to know enough to change its configuration or access it to get what you want. (actually this sounds like my job - technical support)

      Long before he was ever caught I had read about his exploits in computer magazines and the paper. His capture, and the scadal about his stay in federal prision I think made him famous. He's the only one - aside from those stuck in Guantanomo Bay who have been held without trial.

    6. Re:Con-man gains fame at others expense... by idlemachine · · Score: 2, Insightful
      I'm so sick of this guy's so-called "hacker" fame.

      I'm so sick of people here being proud of their ignorance. If you don't know what he's done, isn't it up to you to find out before passing judgement?

      Oh right, it's up to everyone else to do that for you as well.

    7. Re:Con-man gains fame at others expense... by tmasky · · Score: 2, Insightful

      As I've said to people previously.. Nobody will ever know about the greatest hacker who ever lived. Well, maybe I stole that from somewhere, but meh..

    8. Re:Con-man gains fame at others expense... by flyingsquid · · Score: 5, Insightful
      The insurgency in Iraq is a good case of how effective the human element is. The guys apparently know pretty much everything that's going on because they have moles and informers in the government, and because they can blackmail and threaten people for information. They just managed to take out a couple of the people in the Hussein trial. Meanwhile, for all their high-tech satellites, unmanned aerial vehicles and NSA technology, the U.S. still can't figure out where the hell Zarqawi is.

      Likewise, the U.S. was able to get intelligence on the Soviets by sending a sub to tap an underwater cable in the Sea of Okhotsk. This cost tens of millions of dollars. For a couple million, the USSR bought off Aldrich Ames and got whatever intel they wanted. All in all, being able to manipulate people is probably a lot more useful and dangerous skill than being able to manipulate technology.

  9. C&C by shannara256 · · Score: 5, Insightful

    As CABAL said in Command & Conquer: Tiberian Sun,

    "The systems are impenetrable. There are no weak points. The technology is without flaw. The Human element, as always, is riddled with imperfection."

    1. Re:C&C by Anonymous Coward · · Score: 3, Funny

      Just wait until he gets to Doom 3.

      "Crap, it's dark!"

    2. Re:C&C by Jason+Ford · · Score: 2, Funny

      Ah, nice try. Three-headed monkey. Fool me once, shame on--shame on you. Fool me--you can't get fooled again.

      (three-headed monkey dances by)

      --
      I did not become a vegetarian for my health, I did it for the health of the chickens. --Isaac Bashevis Singer
  10. Social Evolution by MrAsstastic · · Score: 4, Insightful

    This is exactly how things become worse as time goes on. Now regular folks are going to become more rude and less interested in working with you to get things done. Trust me, the sheeple don't know how to defeat social engineering. They are used to fear and terror and will be distrustful of your attempts to get work done. A few can defend against rogue attempts to illicit secure information, but most will just be jerks about it and everybody hurts. More negativity. Well, it's something to work on and I guess that's what we do here on Earth...we work on stuff together. We talk about it on Slashdot, we IM our buddies and send them interesting links. Slowly their minds change to our influence. I found out at an early age how easily I can manipulate good people and it sickens me. I grew up, matured and avoid it at all costs. But it does come with a heavy price. Sometimes it is very hard to deal with good people. Especially stuck down here in my parents basement, looking for light swords and good time travel techniques. Forward into the fray.

  11. Policy, Process, Training. And still, holes. by jafac · · Score: 5, Insightful

    My employer holds regular training sessions for all employess on computer security, with a strong focus on resistance to social engineering methods. There are also several levels of the training, a basic course for the rank-and-file, a higher level course for those higher-ups and engineers who have to protect subcontractors and customers proprietary data, and a more intense set of courses for the IT and security folks. (We manage both physical and information security).

    Have we had information stolen? Yes. We've had unscrupulous employees go to work for competitors and give them proprietary data, we've had subsidiaries sell controlled technology to foreign powers (and got bitchslapped for it too!).

    Point is, machines are easy to secure. More often than not, theyll protect what you tell them to, especially if you have competent engineers. But the weak link is ALWAYS the human one. The most careful companies can apply careful policy, process, and training, like my employer does, and they can also hire tons of babysitters, big brothers, and such. And the information still flies out the door.

    --

    These are my friends, See how they glisten. See this one shine, how he smiles in the light.
  12. more paranoia = more mental institutions by Anonymous Coward · · Score: 2, Insightful

    There seems to be an alarming trend towards insane levels of paranoia, especially here in the US. At the same time there is an unprecedented increase in cases of clinical paranoia and related mental disorders. I wonder if there is any correlation... For sure there are thousands of security related companies doing good business and politicians pushing their agendas.

    1. Re:more paranoia = more mental institutions by Sloppy · · Score: 3, Insightful

      Paranoia is when you think people are out to get you, without having a reason to think that. Good security is about thinking people could be out to get you, and planning for the worst case scenario. You don't have to be paranoid to be secure, you just have to accept that shit can happen.

      --
      As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
    2. Re:more paranoia = more mental institutions by NichG · · Score: 2, Insightful

      This isn't necessarily a recent development though. I'm sure we had the same sort of paranoia during the cold war - the very essence of the cold war was paranoia about communism and communist world powers at some future point acting against the US.

    3. Re:more paranoia = more mental institutions by RWerp · · Score: 3, Insightful

      They were acting all the time against the US and Western democracies, so it wasn't a paranoia at all.

      --
      "Long run is a misleading guide to current affairs. In the long run we are all dead." (John Maynard Keynes)
  13. trade off by delirium+of+disorder · · Score: 5, Interesting

    Technical or human, good security requires balencing convenience and control. If you give your employies the power to refuse information to potential customers, you gain control and security but loose convience and maybe money. If you tighten your network down so much that users have to jump through hoops to send files to each other, you may be more secure, but the hassle will lead to lost productivity. You can't try to too hard for control or for freedom. You have to weigh threat and risk. You want to ensure against potential disasters, and eliminate any more likely security risks. It's probably too costly to treat a low threat but high risk (common) security hole as if it were a disaster. This is why stores find it cheaper to set prices assuming a certain ammount of shoplifting will occur. It would cost too much in lost sales and increesed labor to secure the store against all theft. Training your dumbass users, helpdesk, and even sysadmins to recognise social engneering, might just cost more then any losses from security breaches.

    --
    ------ Take away the right to say fuck and you take away the right to say fuck the government.
  14. Mitnick by Stalyn · · Score: 4, Interesting

    remember this

    --
    The best education consists in immunizing people against systematic attempts at education. - Paul Feyerabend
  15. Dumpster Diving For Info by eric31415927 · · Score: 5, Insightful

    What do you do with your print outs? Do they wind up in the filing cabinet, the shredder, the recycle bin, the trash? I've seen many people trying to be green by chucking their papers in the big blue recycle bin. I'm sure much of this blue-bin fodder should have been shredded.

    1. Re:Dumpster Diving For Info by Anonymous Coward · · Score: 2, Interesting

      Simple answer is to put a heavy duty cross-cut shredder beside that recycle bin or even better one that reduces documents to something resembling confetti. Certainly some paper waste companies do shred the paper they pick up, sometimes right in the truck they use to pick up the recycling. However for important or sensitive information you should not rely on this "service". Also a company rep, manager, or other person should verify that shredding takes place either by casually visiting the pick-up vehicle if they shred on-site or performing a site audit/visit at any central recycling facility to confirm the company is doing what they claim and what you are paying them for.

      FOr myself, if it's particularly sensitive I'll shred the stuff at home.

      Speaking of home and bringing up home workers. Companies should also provide a cross-cut shredder as well as that company computer, printer, or other technology for work-at-home employees. Teach them to shred stuff, even allow them to shred personal stuff if they have them. It will provide some added "noise" to the company confidential shredded documents.

  16. Relevant quote (Schneier): by chris_eineke · · Score: 5, Insightful

    "But if you think technology can solve your security problems [...] then you don't understand the problems and you don't understand the technology."
    - Bruce Schneier

    --
    "All you have to do is be fragile and grateful. So stay the underdog." Chuck Palahniuk, Choke
  17. Definition of geek by EmbeddedJanitor · · Score: 5, Funny

    Has not yet said "no"... actually hasn't been asked yet either!

    --
    Engineering is the art of compromise.
  18. Only useful for a small subset of threats by nasor · · Score: 4, Insightful

    I suspect (but of course can't provide any real evidence) that the vast majority of computer break-ins are by young people who are simply looking for any system to break into, not targeting a specific company. Most 'crackers' probably just pick a known vulnerability and search around for a system that hasn't fixed it yet. They don't particularly care who they break into, so long as they're breaking into somewhere.

    These social engineering attacks that Mitnick has built a career warning people about seem more relevant to situations were the cracker has some very specific goal in mind regarding a specific organization - dedicated industrial spies who want specific information from a particular company, etc. While I'm sure that sort of threat is a concern for many companies, I don't think it's typical of how and why computers usually get hacked into.

  19. Mitnick is an idiot... by Anonymous Coward · · Score: 3, Insightful

    I was part of the "underground" at the same time he was. The people that took chances and did stupid stuff got caught. He fucked up, got caught, and now he's making money lecturing on basics like "teach your employees not to give out a password to a stranger that asks for it." NO SHIT!

    The smart people didn't get busted, and have to work their tails off doing regular sysadmin duties these days.

    1. Re:Mitnick is an idiot... by Idarubicin · · Score: 3, Insightful
      The smart people didn't get busted, and have to work their tails off doing regular sysadmin duties these days.

      Right. Smart. Working long hours for low pay, instead of fame, fortune, and easy work. Hm.

      Sounds like Mitnick's still the best at making people do his bidding.

      --
      ~Idarubicin
  20. Mitnick's never been "inside the fence" by SuperBanana · · Score: 5, Insightful
    We can't expect our employees to be human lie detectors,' Mitnick said. 'One of the most difficult challenges in corporate cultures is getting people to modify their politeness norms.

    Mmm...no.

    This is the problem with Mitnick- he's never been inside of the fence. Ever. He's always been peering in from the outside, either as an attacker or a consultant. Unless you work in IT as regular staff, you don't realize the root causes.

    The problem isn't with training people to say no, or to stick to policies. Especially in a medium to large organization, there's little problem getting people to stick to policies if they make sense or aren't an unreasonable impediment to workflow. The word is "bureaucracy", and so often, it's used by lazy people to avoid work.

    Security problems come from three areas:

    • Security policies written by the incompetent
    • Security policies influenced by corporate politics, such as "oh, the controller will complain if his accountants keep having to change their passwords, we share a boss, and he's got a lot of favor with the boss, so I don't want to piss him off" (see above)
    • Security policies so complex or cumbersome, they're ignored or not followed as strictly as necessary (see above)

    Notice a pattern? Security policies written by the incompetent.

    A company I worked at had to comply with Sarbanes-Oxley regulations. This was interpreted to mean that every 90 days, all the employee domain passwords would expire. Because a large portion of the company used Macs (to make a long story short, you can't easily set up a Mac to let users change Active Directory passwords, much less notify the user their PW has expired and "please change it:"), email and file server access would just stop with no warning, and they'd flood help-desk with calls.

    Typical conversation went something like:

    "...and what would you us to change your new password to?"
    "Harry123"
    "Is that family member's name?"
    "Yes, my husband's."
    "Please pick something else."

    This would go on and on. Some of the passwords people wanted consisted of their username plus "123", their first name plus two numbers, etc. Even worse, their initial password was based off their hire date, and most people never bothered to change theirs- so access to any other employee's email for at least the first 90 days was Dumb Shit Easy.

    It's so incredibly stupid- force password changes every 90 days, but no standards for setting passwords...predictable passwords for new employees...no password auditing(ie runs with John the Ripper or similar)...nothing. Just "make all the passwords expire every 90 days." Brilliant. Why couldn't stricter password rules be enforced? Top management decided it would "aggrivate" employees too much, and I was actually told not to stop employees from picking bad passwords.

    1. Re:Mitnick's never been "inside the fence" by rve · · Score: 3, Interesting

      From my experience in the workplace (100% tech savvy people, it's a software company): On the servers that force users to change their passwords every 90 days, most users use their regular password plus a number, adding exactly nothing to the security.

    2. Re:Mitnick's never been "inside the fence" by devonbowen · · Score: 3, Insightful

      Can someone please explain to me what the point of forcing users to change their passwords every 90 days is? I mean, even if it's implemented "correctly".

      On systems where this is not done, I use random strings as passwords. I know it's for long term use so I commit it to memory. On systems where this is done, I use simple patterns because I don't want to forget it while I'm on vacation. It's a dramatic reduction in security in my case and incredibly annoying. I note that many people even write them down to help their memory.

      The only time I can imagine it helping is if someone breaks into your system. It means their time to do damage is limited. But not by much. On a system that requires new passwords every 90 days, I've got an average of 45 days of access before I lose it. 45 days!! Yipee!! Not much I can't do in that amount of time.

      Devon

  21. Re:no shit, kev by cheekyboy · · Score: 2, Insightful

    1. find something obvious
    2. organize a corporate speech session
    3. charge $4000 for a talk
    4. profit.

    --
    Liberty freedom are no1, not dicks in suits.
  22. That's what LC5 is for... by Seng · · Score: 2, Funny

    If you need to log in, crack the password yourself first :P

  23. It's at least as much a software problem by jesterzog · · Score: 4, Insightful

    Kevin Mitnick is looking at it from companies' points of view right now, but I think the whole problem is really created by some fundamental flaws in software architecture patterns and how most software these days interacts with the users. (Arguably it's as much a fault with the operating systems as everything else.)

    I don't think that there should be that much of a burden put on the user to be responsible for saying yes or no all the time. So much software that's out there today directly bombards the user with so many questions about things that they don't understand, care about, or have time to deal with, that it's not practical for most people to spend so much time caring about what they're being asked.

    Passwords, which Kevin Mitnick also talks about, are an equally bad design. They're there for the convenience of the machine -- not the person using it. Most people aren't mentally capable of remembering and matching lots of different passwords for different services, certainly not if they're supposed to (or forced to) change them every few months. It's no surprise that in order to get their actual work done, people are simply going to resort to predictible patterns or writing down secret information.

    I can set aside the time for dealing with these sorts of things, and I'm sure that many people here can... but then I have more than a passing interest in computers and what's going on inside mine. For many more users out there, a computer is just a tool that's used towards something that's much more interesting to them, and dealing with the tool is one of the last things they want to care about.

    Teaching people to "say no" is certainly part of the equation, but it won't work beyond a certain point. I don't know what the answer is, whether it's reducing the number of options over all software, trying to make more intelligent decisions without asking the user, arranging things so that people's software is generally configured entirely by an administrator who understands the issues, or something else. I think it's important to realise, though, that research about reducing social engineering in software is at least as important to security as researching technical security holes. It's as much of an HCI problem as a security problem.

  24. Um, they have no freaking problem saying "no". by Caspian · · Score: 4, Interesting

    It's just that they don't know when to say "no" versus when not to say "no".

    Any dealing with any large, bureaucratic organization (a government bureau of any stripe, any telco, any cable company, any other sort of "utility", eBay/PayPal, Microsoft, IBM, etc.) will demonstrate quite aptly that no, they have no bloody problem saying "no". You can make a reasonable request and they'll quite cheerfully say "no" since it isn't part of their "script" to say "yes". (Then they'll tell you they're "sorry" they couldn't say yes. They aren't.) Meanwhile, the "bad guys" probably know how to work the system anyhow, and can get them to say "yes" by understanding said "script".

    Simple example: I do business under my initials, and PayPal wouldn't let me change the name on my account to my initials for "security reasons". Even after I provided proof that both of my bank accounts had already been changed (to my initials). Even after I went back and forth with them at least half a dozen times. I finally had to go in the "back way" via talking to an ex-PayPal employee, who talked to a current PayPal employee, etc. etc...

    They wouldn't change my name to my initials despite indisputable (and verifiable) proof from two established brick-and-mortar banks, yet they have absolutely no problems letting you set a crappy-ass password on your account... You see? Their priorities are backwards. They love saying "no", but they have no clue when to do it and when not to. The end result is that they suffer not only from security risks, but from bad PR.

    --
    With spending like this, exactly what are "conservatives" conserving?
  25. I'm surprised. by Kadmos · · Score: 3, Insightful

    Honestly this is very suprising to me. I own and run a small business and people try and scam us all the time. Examples include dodgy telephone directory listings, website hosting, domain hosting, overpriced stock and people just generally phoning us and trying to sell us every piece of crap under the sun. This is not just scammers, it's also local sporting groups, charities, schools, churches etc all seem to think we are here for their sole benifit. It never seems to occur to any of them that we get asked ten times a day to hand over money for no benifit to us. It sounds like I am bitter, but I'm not, this is just reality.

    I don't mind donating, I give time and money every week to several organsisations (of *my* choice), but most of them have never even been a customer before.

    So actually thinking about each and ever deal/agreement I make has become second nature, it's easy to tell when somebody is trying to scam you really. If people start asking intimate questions: "who do you have your telephone with? it's a scam. If they ask "are you the owner of this business" and then ask *another* question about the business it's a scam.

    If they really had anything to do with your business they don't need to ask who you are, because they already know.

  26. FREE MARTHA! by sulli · · Score: 5, Funny

    oh wait .. never mind...

    --

    sulli
    RTFJ.
  27. ** _ by Nailer · · Score: 4, Funny

    offer is only valid with purchase of Kevin of equal or lesser size

  28. This is news? by swordgeek · · Score: 2, Insightful

    Is there anything here that hasn't been said better already by Bruce Schnier? For that matter, is there anything here that Mitnick himself didn't already say in his trial?

    People are the weakest link in any security system. This is so well known that it's not even worth talking about, unless you have a new way around it. Kevin, sadly, does not. Training people doesn't work. Not only is your security only as strong as the weakest link in the chain, but it's only as strong as the weakest occurence of that weak link. In other words, unless you can GUARANTEE that 100% of your employees won't be susceptible, training them beyond the obvious (which should be presentable in a half-hour lecture) isn't a useful endeavor.

    Schnier has it right: Protection is only a way of giving yourself more time for the detection and response mechanisms to kick in. You won't ever get a secure system by locking all the doors.

    --

    "People who do stupid things with hazardous materials often die." -- Jim Davidson on alt.folklore.urban
  29. Too Much Security by logicnazi · · Score: 3, Insightful

    Social engineering is effective quite simply because we have alot of annoying mostly pointless security measures and then real security measures with no good way to tell them apart.

    Look, if the same security policy that tells you not to let *anyone* into the building without a key card tells you not to tell anyone your password you are likely to ignore both. In most buildings there is no good reason not to hold the door for the person behind you but a very good reason not to share your password.

    People aren't computer programs they need not only to be told what policies to follow but which ones are the important ones and which ones are just meant to keep bums from sleeping in the lobby.

    --

    If you liked this thought maybe you would find my blog nice too:

  30. To the anti-Keven crowd by chadpnet · · Score: 4, Informative

    As I clicked on the comments link and expected to find a decent collection of Kevin flames, I knew I'd have to throw my two cents in.

    To the ones that claim that this is old news, or that Kevin isn't as "leet" as many think; I advise to take your comments with a grain of salt. Anyone who has actually read his book, The Art of Deception, will appreciate Kevin's viewpoints. The truly great hackers use a good mix of social and technical engineered tactics to comprise security. I give you the advice is outdated and isn't news, but his advice will always outlast ever-changing technology. As a bonus he gives you open-sourced ;) policy suggestions that would be a nightmare for admins to write themselves.

  31. Let My People Go! by mo^ · · Score: 2, Funny

    does this count?

    --
    bah!*@%!
  32. Wielding the Clue-Stick... by Genda · · Score: 2, Insightful

    I have a good friend who's an ex-spook, and a major player in the security community. She mentioned in a magazine article "It's simply amazing to watch IT Managers putting steel safes on what amounts to be Japanese paper summer houses... the front door isn't your problem..." Genda

  33. biometric authentication social engineering by Bazman · · Score: 2, Funny

    "Hi, I'm calling from tech support, I need your fingerprint and iris scan, so could you please chop off your index finger, gouge your left eye out, and send them to me please? That's great thanks."

  34. FREE TIBET! by Hektor_Troy · · Score: 4, Funny

    Limit: One per customer.

    --
    We do not live in the 21st century. We live in the 20 second century.
  35. not quite by commodoresloat · · Score: 2, Informative
    He was considered an outstanding hacker before he got caught. They wouldn't have gone after him as mean-spiritedly as they did if he had not hacked circles around the people after him. An undercover agent (who happened to be bald) that was after him found that his private phone numbers had been switched with the number for the hair club for men. Mitnick was a juvenile prankster, but his hacking skills were legendary, and his pranks pissed off a lot of people who ended up wanting to throw the book at him.

    And when his archrival finally caught him it was only with the help of the FBI, the ISP he had been hacking, and a New York Times reporter who consistently exaggerated Mitnick's crimes and turned him into a symbol of America's fear of technology. His getting caught certainly made him even more of an icon -- especially since they went after him so viciously -- but his success as a hacker did not stem from being caught, as you say.

  36. FREE MAC MINI by xtracto · · Score: 2, Funny

    mmm does anyone have a link??? =oP

    --
    Ubuntu is an African word meaning 'I can't configure Debian'
  37. 40 years from now by DeanFox · · Score: 3, Insightful


    Whether I like the messenger or not, Mtinick is right. So long as humans are part of the security equation, we will have insecure systems. The song he's singing is true. A tune few are paying attention to. Like death, social engineering has no solution today, so it's avoided with discomfort or even ignored. Three people can keep a secret if two of them are dead. Social engineering is that last security hole still left unpatched.

    I work in IT and I can blind dial any extension, introduce myself as employee X from Corporate IT and without any pretense, obtain a user ID and password. If I am trouble shooting a user complaint and ask their user ID, their password is often offered without me even asking for it. The vast majority of viruses rely on social engineering, as do tool bars, spyware, etc. I think Mitnick is right that the problems we have today are less technical than social. Most of the security holes in Windows could exist unexploited if it were not for social engineering.

    Jack LaLane, the fitness guru, was viewed 40 years ago as a freak. It may take 40 years but once society finds a way to resolve or at least seriously takes an interest in the social engineering problems of network security, I wonder if history will label Mitnick as an early adopter or label him a "before his time" genius.

  38. Re:Being a terrible social engineer by WarpGiGA · · Score: 2, Insightful

    "but the guy's a criminal, end of story."

    Correction: "He was a criminal."

    Just because a person was cute a young age, doesn't make him cute until he/she dies. Furthermore Mitcnick has served time in jail, so he is by law redeemed of his actions..(?)
    To even remotely suggest that he is in similar category as paedophile's is just idiotic and/or ignorant.
    Although it is probably safe to say that he won't be cleared for CIA related work, I would have no problem hiring him as a consultant on any security matter regarding my business..

  39. Its not about stupidity by helix_r · · Score: 2, Insightful


    Everytime computer security issues come up on slashdot, a torrent of geeks always chime in about how things are so bad because of "stupid" people.

    In fact, there is such a sys-admin (excuse me, I mean "architect") in my office. He loudly complains all day about how the "stupid" and "incompetent" are always making his life difficult and wasting his time.

    What I don't think he realizes is that people are afraid to approach him with questions and problems. Those that do are often quickly and rudely dismissed or put on hold for extended times.

    Here's the big problem-- if the "stupid people" in the office, you know, like scientists, professionals and others that make money for the org, dread interacting with the IT guy (I mean architect), they will go elsewhere when there are problems. If they are brushed aside when they ask about "the internet not working", they will be less likely to say anything when something _really_ goes wrong.

  40. Re:no shit, kev by bullitB · · Score: 3, Funny

    Actually, I think this was a case of social engineering. He actually was able to convince the crowd that security and technology are unrelated.

    Mitnick, you are a clever one.

  41. Re:Locking down computers by cbr2702 · · Score: 2, Insightful
    you dont work in a real IT environment.

    I do, actually. It may be a more reasonable place than where you work, but it is still real.

    marketing manager that demands he needs admin rights. other managers that think they need admin rights so it snowballs and then corperate deems that most have admin rights

    If you are reasonable with people, they will be reasonable with you. Why does the marketing manager need admin rights? If she does, give them to her. If she is just demanding for no reason, say 'no'. Where I work departments can buy their own machines, but we don't have to take care of them if they choose to, so we have some leverage.

    or better yet the idiots in the NOC set the global user profile to put them in the administrator group for some failed attemptto push out a path and forgets to move everyone back.

    The NOC's first move was excessive, and then they were negligent. If they keep being incompetent, get someone who isn't.

    corperate IT is hell. as the NOC morons are sure they know more, the managers demand more access or threaten your job, then bitch that they clicked on a strange attachment and want to know why you are not protecting them.

    I'm happy I don't work where you do.

    solution? thow their asses under the bus. when a manager or Director infects his computer and then the office, ANNOUNCE who it was, espically to the IT heads.

    No, that's not a very good solution. That will just get more people mad and unreasonable. If someone has no need for a dangerous privlige, don't let them have it. Be willing to send out low-level techs to do admin-work on people's computers and install the software they don't have rights to install. Don't humilate people.

    --


    This post written under Gentoo-linux with an SCO IP license.
  42. Re:Being a terrible social engineer by pandrijeczko · · Score: 2, Insightful
    If you're in the UK like me, you know the story of Tony Martin, the farmer who disturbed two burglars in his house- for those that don't, Tony Martin served 5 years in prison for killing one of the burglars and wounding the other in the leg with an illegally possessed shotgun.

    I can't remember the names of the burglars but the BBC have just paid the one who survived £4500 for assisting in making a documentary about the case.

    I don't sympathise fully with Tony Martin but I do not believe that a convicted criminal should be allowed to make personal profit as a result of a crime they have committed - no different to what Mitnick is doing now.

    Yes, he's served his time, he's paid his debt to society but he'd be a nobody now were it not for his previous hacker reputation.

    --
    Gentoo Linux - another day, another USE flag.
  43. I've worked with Kevin... by GeneralEmergency · · Score: 2, Funny


    ...so I know what I'm talking about.

    Kevin is intellectually tenacious. If he wants something, usually knowledge about the inner working of something or some secret. His will not give up until he learns what he wants to know.

    What Kevin has produced is a comprehensive disclosure of the techniques and methodologies that people with hyper-curiosity use to get at YOUR secrets.

    Now little man, goto the book store and buy a copy of "The Art of Deception" by Mr. Mitnick (to you) and if you read it through to the end, you will find my real name listed in the acknowledgements.

    --
    "A microprocessor... is a terrible thing to waste." --
    GeneralEmergency
  44. Strong Passwords are worthless by fhage · · Score: 2, Interesting
    as soon as keystoke loggers are introduced into an organisation.

    My org was hit bad. One could ssh into a remote host and within seconds the box would be rooted and keystroke loggers installed.

    No amount of "social" training can solve this problem.

    BTW. The software based loggers are professional quality. They are undetectable without booting from known good media and examining the kernel, all its modules, and all applicatiions. Hardware based keystoke loggers are available too.