Slashdot Mirror


No-Fail Identity Theft – Live and In Person

ancientribe writes "A researcher performing social-engineering exploits on behalf of several US banks and other firms in the past year has 'stolen' thousands of identities with a 100 percent success rate. He and his team have posed as investigators for the FDIC (among other things), and numerous times have literally been able to walk out the door with pilfered identities. The reason: organizations are typically so focused on online ID theft that they've forgotten how easy it is for a criminal to socially engineer his way into a bank branch or office and physically hack it."

4 of 214 comments (clear)

  1. I guess some places are just lax by BenEnglishAtHome · · Score: 5, Interesting

    None of that crap would pan out where I work.

    Need help getting through a door? Sure, people will let you through a door if you're lugging a load. Then they'll see you don't have your badge on, offer to help you find the office and person you're looking for, and if you don't know what name or location to give, they'll stick right with you until you figure it out or security comes along to help.

    Selling copiers? "Oh, man, dude, nobody on this floor has the authority to buy anything! Lemme walk you over to the facilities guy that you *must* have an appointment with. He'll get you a temp badge or an escort if you need to look around."

    New hire? "Gee, ya know, I hate to be a pain about this but you really do have to keep your badge on in the building. Lemme hold your box while you find it."

    Lost your badge? "Gee, ya know, you're gonna get hassled a bunch without it. Do you know where Kathy's office is? Let me show you; she can issue you a temp badge for the day."

    Lugging in a server or anything that looks remotely computer-like? The security guard will have you sign in and call down someone from IT to escort you.

    Visiting executive? Unless you're the commish, in which case you'll be covered by a phalanx of security, even the lowliest of the low in this place will give you a friendly wave, say hi, and offer you a lanyard for your badge while you're in the building. "Oh, that's OK, I can wait till you find your badge. Do you want me to show you where you're going/where to get a temp badge/to security?" In fact, this is one of the few times a data input operator can pull rank on the highest executive in the organization and you'd better believe that no office lacks for people who would relish the opportunity.

    Bluff your way past security and take an elevator ride to an upper floor, looking for something? Big deal. All the doors are on card keys and if you knock, the person who answers is going to lead you right back through the "Gee, I hate to be a pain about this but you really have to wear your badge in the building" routine.

    Walking around in the hall looking semi-lost because you got in but realize you can't get through any of the doors? You'll be directly challenged by someone who will walk you directly to your manager (if you can provide a name and location) or directly to security.

    If by some total breakdown (say, you've got a decent fake badge and you piggyback on someone to get through a door) you get into the work area and plop down in a conference room, you're gonna get caught in short order. Plug in your laptop? If you haven't pre-reserved the room, you'll trip port security, that port on the router will shut down, the telecomm lady will get an automatic page and head up to that conference room to see who's screwing around by plugging in an unregistered MAC. Just turning on a laptop with wireless enabled chances setting off the scanner that's sometimes running in every building; in that case, you get a quick visit from scary men with badges and guns. You're a contractor on site and you plug in a wireless access point? See the sentences immediately previous, plus you get tossed out, fired if you're a sub, lose your individual security clearance, and the overall contract holder gets in seriously hot water. Just sit there and try to look important? The conference room reservations are controlled by the nearest secretary. As soon as s/he sees you in the room, you'll get asked to do a formal reservation. "If the room is free, you can have it, but I need your name and badge number for the log book. By the way, where's your badge?" In offices where the conference rooms aren't tightly controlled, people get used to dropping in so if you're sitting there without a badge, you're going to get questioned. If you don't know the right jargon, the right person to say you're working with, the right organizational attributes to assign to yourself, you're going to be questioned. Even the most tim

  2. Re:The biggest exploit for any system by SydShamino · · Score: 5, Interesting

    Better than that, I think any good university should take your (correctly modded) interesting suggestion and employ it for their own use.

    1. On a weekend or another "off" time, the university hires someone to set up a table outside the UC, where credit card vendors often wallow.

    2. The person sits at the table and offer credit card applications to students. He gives them lollipops or something equally stupid as reward, or just promises them a T-shirt in the mail once their application has been approved.

    3. He packs up and leaves in 30-45 minutes.

    About a week later, the university contacts anyone who filled out an application, explains to them that the person was posing as a ID theft criminal posing as a credit card salesman, and that, had it been an actual criminal, their credit would already be trashed.

    That could be a sober lesson for many naive young college kids. I bet the local police would be happy to orchestrate something like this.

    --
    It doesn't hurt to be nice.
  3. Inside vs. outside badges by Animats · · Score: 5, Interesting

    Operations serious about security do a badge exchange when you enter the facility. You present your "outside" badge, which is validated at the security checkpoint, and exchange it for your "inside" badge, which never leaves the facility. This forces the security people to really check your outside badge, and makes the inside badges harder to copy, since they're not seen outside the facility. Information about what areas you're allowed to access appears only on inside badges. Outside badges won't open anything; inside badges may also be keys.

  4. Funny but true story... by lbates_35476 · · Score: 5, Interesting

    I was watching a professional thief turned consultant on TV a few years ago describe his best and easiest scam. He would get a rent-a-cop uniform and stand outside a bank branch somewhere at the night depository. When people came to the bank to make their night deposits, he explained that it was broken and the bank had hired him to collect the bags. He claimed that most people actually gave him their night deposit bags!