Slashdot Mirror


How To Rob a Bank: One Social Engineer's Story

itwbennett writes "Today's criminals aren't stealing money — that's so yesterday, according to professional social engineer Jim Stickley. In an interview with CSO's Joan Goodchild, Stickley explains how he's broken into financial institutions large and small, and stolen their sensitive data. In a companion story, Stickley walks through the steps he takes to fool clients into thinking he's there for fire safety, while he's really proving they are an easy target for a data breach."

111 comments

  1. Small time by Hatta · · Score: 5, Insightful

    The real big criminals own the banks.

    --
    Give me Classic Slashdot or give me death!
    1. Re:Small time by Anonymous Coward · · Score: 5, Informative

      The real big criminals own the banks.

      Exactly, see "The Best Way to Rob a Bank Is to Own One: How Corporate Executives and Politicians Looted the S&L Industry" by William K. Black. The basic concepts and problems from that debacle are still in play with our current mess.

    2. Re:Small time by ackthpt · · Score: 5, Insightful

      The real big criminals own the banks.

      Own?

      Nooooo....

      The really big criminals work in top positions of banks and are well connected in government, so they only have to look slightly admonished for a few weeks after nearly bringing down the entire economy of the West and then it's back to business as usual.

      They don't own banks, they pwn banks.

      --

      A feeling of having made the same mistake before: Deja Foobar
    3. Re:Small time by Anonymous Coward · · Score: 1

      Best way to derail an interesting story: inject politics into the discussion.

    4. Re:Small time by Anonymous Coward · · Score: 0

      The real big criminals manage the banks.

    5. Re:Small time by dkleinsc · · Score: 1

      In fact, there's a worthwhile read on precisely this topic: The Best Way to Rob a Bank Is to Own One

      --
      I am officially gone from /. Long live http://www.soylentnews.com/
    6. Re:Small time by Mashiki · · Score: 1

      The big criminals are the guy sitting in government. Hate to break the news to you. Banks can only work with the regulations given, or forced on them. Remember that housing bubble and collapse? Did you enjoy the government forcing banks to loan out money to unsafe groups? I bet you did!

      --
      Om, nomnomnom...
    7. Re:Small time by kilfarsnar · · Score: 1

      If that were the case, why did the housing bubble happen outside the US as well? US regulations don't apply outside the US, yet there was a global bubble. how do US regulations on bank account for that?

      http://seekingalpha.com/article/124306-the-global-housing-bubble-it-s-a-small-world-after-all

      --
      "What the American public doesn't know is what makes them the American public." -Ray Zalinsky (Tommy Boy)
    8. Re:Small time by Mashiki · · Score: 1

      CDS and cross-ownership of debt. That's how. The same reason why there was a massive implosion of the mortage and banking system in iceland. On average the mortgage there was divested by nearly 60% into other non-standard currencies and debts.

      --
      Om, nomnomnom...
    9. Re:Small time by pnutjam · · Score: 1

      I think you got him, good rebuff. All these morons want us to put all your eggs in one basket, when the real problem last time was too many eggs and not enough baskets. Maybe that's the real hazard of an inflation based economy?

    10. Re:Small time by Haffner · · Score: 1

      Part of it is that when you inflate an asset class domestically, there will be a reaction abroad. Let's say the real asset value of a house in the US is $X, and an equivalent property elsewhere is $Y. If in the US $X house is overpriced to, say aX where a>1, we would expect to see an equivalent investment abroad rise to bY, where there is a function f(a) = b (as there won't be a perfect correlation). HOWEVER, the net result is that one could hedge out most of the location/currency risk and be left purely investing on the value of the home. So, abroad people start buying houses at bY, which appears to be the rational price. Then, when everyone finds out that in the US the real value of the home is $X, prices fall, and pull down houses abroad to $Y. TLDR: housing abroad is affected because housing getting more expensive in the US makes housing more attractive elsewhere, and investors will try to arbitrage that.

      --
      "Going to war without the French is like going deer hunting without your accordion." ~General Norman Schwarzkopf
    11. Re:Small time by swalve · · Score: 1

      I don't think you know what a CDS is.

    12. Re:Small time by Mashiki · · Score: 1

      Funny that. I guess I've never made money in the market by knowing what countries are going to issues a CDS and taking advantage of the forex market either. Oh wait...

      --
      Om, nomnomnom...
  2. As a victim of theft by esocid · · Score: 3, Insightful

    by the banks, I'm ok with the role reversal.

    --
    Absolute power corrupts absolutely. indymedia
    1. Re:As a victim of theft by ackthpt · · Score: 3, Insightful

      by the banks, I'm ok with the role reversal.

      Old bumper sticker: Don't Steal - The Government Hates Competition

      New bumper sticker: Don't Steal - The Banks Hate Competition

      --

      A feeling of having made the same mistake before: Deja Foobar
  3. Euphemisms by drooling-dog · · Score: 1

    So when did con men become "social engineers"? It sounds almost like a respectable profession.

    1. Re:Euphemisms by Anonymous Coward · · Score: 2, Insightful

      When they get paid by the boss of the people they are engineering to help prevent real con men from doing it.

    2. Re:Euphemisms by cusco · · Score: 5, Insightful

      It can be. I had an instructor for a computer security class whose day job was doing pen tests for financial institutions. He and his partner would arrive at a site and set up in a random meeting room. While one guy started unpacking the trunk load of computers and getting set up the other would get on the phone and start dialing branch offices. Whoever answered on the other end would get a line like, "Hi, I'm Brad, the new guy on the Help Desk. We need to reconfigure the router in your office this afternoon. The guy who normally does that is home with his sick daughter, and the only other login on the router is your manager's. Can I get their username and password?"

      In two years they had never failed to get a manager's username/password by the time they were finished setting up the equipment.

      --
      "Think about how stupid the average person is. Now, realise that half of them are dumber than that." - George Carlin
    3. Re:Euphemisms by ackthpt · · Score: 4, Informative

      So when did con men become "social engineers"? It sounds almost like a respectable profession.

      Beg pardon, mate, but con is short for confidence, as in, they gain your confidence before nicking your lunch money.

      Social Engineering is just a new-fangled label for probably the 3rd or 4th oldest profession in the world.

      --

      A feeling of having made the same mistake before: Deja Foobar
    4. Re:Euphemisms by couchslug · · Score: 1

      "It sounds almost like a respectable profession."

      So did banking. The masters are utterly corrupt, which has removed any moral reason to respect them or their property. I shed no tears for the rich when they lose what to them is a pittance.

      --
      "This post is an artistic work of fiction and falsehood. Only a fool would take anything posted here as fact."
    5. Re:Euphemisms by ackthpt · · Score: 2

      "It sounds almost like a respectable profession."

      So did banking. The masters are utterly corrupt, which has removed any moral reason to respect them or their property. I shed no tears for the rich when they lose what to them is a pittance.

      The bad bankers (and I don't mean inept, they're bad in a different way) have figured how to game the system. It's like they found the cheat codes to Super Mario to make him run faster, fly better or be invulnerable. It's the position of government to enact laws, as demanded by the people, and to place auditors in place, as also demanded by the people, to see this sort of gaming the system doesn't take place. The problem is the bankers have realized they can openly weep crocodile tears and certain people within the government will say, 'There, there, we'll back off with the mean old auditors and regulations so you can do business the way you want to'

      In my experience the bigger than bank, the bigger the team of auditors and the sharper their pencils should be.

      --

      A feeling of having made the same mistake before: Deja Foobar
    6. Re:Euphemisms by SirGarlon · · Score: 1

      Social Engineering is just a new-fangled label for probably the 3rd or 4th oldest profession in the world.

      One that's less respectable than its predecessors, prostitution and banditry.

      --
      [Sir Garlon] is the marvellest knight that is now living, for he destroyeth many good knights, for he goeth invisible.
    7. Re:Euphemisms by EvilBudMan · · Score: 1

      I thought about how stupid people can be and I can say with certainty that 50% are below average.

      I think it's stupid. People that really rob banks don't have the money to buy 50 computers, uniforms with badges and vans painted with company logos.They go after credit card info by hacking or the old at gunpoint way. Even though it could happen that way it never has because with too many people involved in a robbery, someone will talk. So you would not get stopped right away but you have then left many ways for the police to catch you later on.

      Like someone else said social engineer = con artist. They may take what you have and you may figure out real fast who it was. I guess be prepared for a trip out of the country if you used methods like that.

      Banks or actually the tax payer gets taken by all of this lax security on credit and debit cards.

    8. Re:Euphemisms by Domint · · Score: 1

      I thought about how stupid people can be and I can say with certainty that 50% are below average.

      So can I. That's because that's how averages work, by definition.

    9. Re:Euphemisms by zwede · · Score: 1

      No, dummy. That's how medians work, by definition.

    10. Re:Euphemisms by CSMoran · · Score: 1

      I thought about how stupid people can be and I can say with certainty that 50% are below average.

      So can I. That's because that's how averages work, by definition.

      Exactly! Like when there's a test and out of 50 pupils 49 score 100/100 and one of them scores 0/100. The average score is then 98 and exactly half of the students are below the average, right, oh wait...

      --
      Every end has half a stick.
    11. Re:Euphemisms by EvilBudMan · · Score: 1

      Slow down there is no gravity but the Earth sucks.

    12. Re:Euphemisms by Anonymous Coward · · Score: 0

      Data: 1, 1, 1
      Median: 1
      50% of quantity of data: 1.5
      % quantity of data below median: 0

    13. Re:Euphemisms by uninformedLuddite · · Score: 1

      People that really rob banks don't have the money to buy 50 computers, uniforms with badges and vans painted with company logos.

      Don't know too many bank robbers do you?

      --
      The new right fascists are bilingual. They speak English and Bullshit.
    14. Re:Euphemisms by EvilBudMan · · Score: 1

      Yeah bank presidents and such. I know a few.

  4. Not stealing money? by PuckSR · · Score: 1

    Yes...they are stealing money. They just aren't doing it directly. EVERYONE who steals does it for the money. The guy who steals bread to feed his family would be just as likely to steal money to buy the bread if an opportunity presented itself. These guys are stealing information....that they will then sell to make money.

    Unless you are stealing decorations from Pier 1 in an attempt to make your home look like a twisted and freakish version of a "Better Homes and Gardens" cover, you are stealing money...just not directly.

    1. Re:Not stealing money? by Anonymous Coward · · Score: 0

      Unless you are stealing decorations from Pier 1 in an attempt to make your home look like a twisted and freakish version of a "Better Homes and Gardens" cover, you are stealing money...just not directly.

      I knew someone who did JUST that. It was freekish. He also stole just because he could.

    2. Re:Not stealing money? by Anonymous Coward · · Score: 0

      While that is true for the majority; after all money is just the single unit that represents all resources from materials to labor, there is the minority that does steal for personal reasons (political statements, religious beliefs, etc) but if it involves banks, yeah, end result will be money.

    3. Re:Not stealing money? by Anonymous Coward · · Score: 0

      I dont, I steal it for the THRILL! I throw the money in the trash or hand it back to them when done. Maybe take a nice long sniff of it first....
      I know a guy that Steals it for the education, he is making a log of money serial numbers for a research project.

    4. Re:Not stealing money? by Anonymous Coward · · Score: 0

      Some steal for happiness, something even money can't buy... Myself, I prefer to steal happiness directly.

    5. Re:Not stealing money? by shadowfaxcrx · · Score: 1

      The point was that they're not stealing physical money. As in, not running out of the bank with bags full of bills.

      --
      "I disagree with you" does not equal "flamebait."
  5. Duh by Niris · · Score: 4, Interesting

    You can talk your way into almost anywhere by claiming you're from IT. A couple years ago I did these server upgrades for bank of the west. No ID cards or anything, just walk in and do what you want.

    1. Re:Duh by pspahn · · Score: 2

      One of the more insightful comments from Art of Deception (or Intrusion, don't remember which one) was that even a machine that doesn't work is a vulnerability.

      "Yes, hello. I'm here to fix your broken machine."

      --
      Someone flopped a steamer in the gene pool.
    2. Re:Duh by Anonymous Coward · · Score: 0

      if you don't even have to care about getting caught, then coming up with the self confidence to do it is pretty easy too. which is what this guy was doing.

      just reminds me of some simpsons ep..

      in other news, if you're just out to prove that hitting someone with a baseball bat is easy, it's pretty easy to do it.

  6. as a former security auditor myself... by xxxJonBoyxxx · · Score: 4, Interesting

    As a former security auditor myself, I'd attack the voice response units. Quite frequently those boxes (often standalone towers covered with a quarter inch of dust) were neglected in the corner, with no IDS, no one checking logs and frequently no automatic lockouts. Routed through Skype and/or Google Voice...

  7. Vonnegut? by Sockatume · · Score: 1

    Stickley reads like Kurk Vonnegut Jr. That provided an amusing image.

    --
    No kidding!!! What do you say at this point?
    1. Re:Vonnegut? by treeves · · Score: 1

      Listen. Anyone can sound like Kurt Vonnegut, Jr. Throw in a few oddball names like "Tralfamadorians", and a few quirky cliches every other paragraph, like "And so it goes...", make all the important characters seem like incredible chumps, and you're all set.

      --
      ...the future crusty old bastards are already drinking the Kool-Aid.
  8. I think acting as a fake fireman is a felony by Joe_Dragon · · Score: 0

    I think acting as a fake fireman is a felony and I don't think the real firemen like professional security consultants doing tests acting / saying that they are a fireman.

    1. Re:I think acting as a fake fireman is a felony by Galaga88 · · Score: 2

      Fortunately, the linked story addresses this, and the author talks about how he'll meet with local officials to get permission before playing fire inspector.

    2. Re:I think acting as a fake fireman is a felony by Anonymous Coward · · Score: 0

      If you read the article he states that he always ask the police and fire department first about it and gets permission.

    3. Re:I think acting as a fake fireman is a felony by Joe_Dragon · · Score: 1

      But what if something go Wong or some get's sick and the fake fireman can't help just thing about the LAW SUITS.

    4. Re:I think acting as a fake fireman is a felony by Issarlk · · Score: 4, Funny

      Yes, and these tests are invalid as they address a situation that will never happen in reality: actual criminals will never impersonate fire inspectors, as there's no way they'll manage to get the permission from the local officials.

    5. Re:I think acting as a fake fireman is a felony by couchslug · · Score: 1

      "I think acting as a fake fireman is a felony"

      Is Google broken today?

      --
      "This post is an artistic work of fiction and falsehood. Only a fool would take anything posted here as fact."
    6. Re:I think acting as a fake fireman is a felony by pspahn · · Score: 1

      Apparently pretending to be a football referee is also a felony.

      One day, it just might be a felony to celebrate Halloween.

      --
      Someone flopped a steamer in the gene pool.
    7. Re:I think acting as a fake fireman is a felony by ArsenneLupin · · Score: 2

      But what if something go Wong or some get's sick and the fake fireman can't help just thing about the LAW SUITS.

      Or, more plausible, what if the fake fireman gives bad advice (because he doesn't know his shit, as mentioned in story), people act on the advice, but doing so make things much worse in the event of a real fire...

      I'm sure that he didn't tell the fire brigade that he would "keep walking around rooms, giving them advice on keeping their facility fire safe, even though I really have no idea what I'm talking about. I make stuff up and probably give the worst advice ever. I'll pull out cords and say 'This looks a little bit dangerous.' I'll comment on space heaters. I'm completely winging it. "

    8. Re:I think acting as a fake fireman is a felony by Anubis+IV · · Score: 4, Insightful

      Either my sarcasm detector is broken (please plant your tongue further in your cheek next time), or you've entirely missed the point. Actual criminals don't ask for permission before breaking the law. That's what makes them criminals. They'll still impersonate fire inspectors.

    9. Re:I think acting as a fake fireman is a felony by pixelpusher220 · · Score: 1

      woosh!

      He's not telling the police so the people he's attacking will feel better about it. He's telling the police that there is a 'test' going on and reports about suspicious firemen from that location are likely the 'test' going on.

      It's the same reason why pilots do time in simulators...to train them for when it's *real*. He's effectively training the people he's attacking by putting them through a real world scenario - as far as they know.

      --
      People in cars cause accidents....accidents in cars cause people :-D
    10. Re:I think acting as a fake fireman is a felony by cayenne8 · · Score: 1

      Apparently pretending to be a football referee is also a felony.

      I saw that on the news the other day and I could NOT believe my ears!?!?

      I instantly thought..."OK, we've reached the point to where we have enough....err....too many laws. If they had to come up with making impersonation of a freakin' football game ref a felony, we've gone over the edge.

      --
      Light travels faster than sound. This is why some people appear bright until you hear them speak.........
    11. Re:I think acting as a fake fireman is a felony by shadowfaxcrx · · Score: 1

      Actual criminals are. . Criminals. They don't particularly care if impersonating a fire inspector is illegal.

      As for whether it will ever happen - well, at a lot of places it probably won't because you don't have to get that tricky to get what you want. Just call a high-placed exec's secretary, say you're from IT, and need his l/p to fix his computer. 9 times out of 10 it'll work.

      As he says in the article, the fire inspector ruse comes out when the bank is more sophisticated than most and therefore a harder target.

      I can see it working. We just had a fire inspector in my office a few weeks ago giving me crap about an extension cord. Now, I happen to actually know the guy from past encounteers, and I know that he really *is* a fire inspector, but not everyone in the building does, and no one batted an eye when he was crawling around under desks looking for those nefarious extension cords.

      --
      "I disagree with you" does not equal "flamebait."
    12. Re:I think acting as a fake fireman is a felony by justthinkit · · Score: 1

      More likely it will one day be illegal to not celebrate Halloween. Like it is already illegal to not vote in Australia.

      --
      I come here for the love
  9. And I call by Dunbal · · Score: 2, Interesting

    Bullshit. You mean to say that this guy both steals stuff from bank employees desks AND installs keyboard loggers, and no one at the bank suspects anything like "hey, these guys stole all this stuff from us, maybe they weren't firemen, maybe security has been breached, let's check to see if computers/equipment has been tampered with!"

    From TFA:

    At that point, my partner's job is to start stealing everything he can steal and start putting it in his bag.

    On our way out, we don't want them to know we're done. We want to be able to come back another time.

    Too much mission impossible on TV. This is just an attention whore trying to cash in by pretending to be a crook. Typical of a "security consultant", really.

    --
    Seven puppies were harmed during the making of this post.
    1. Re:And I call by Anonymous Coward · · Score: 1

      This is a bank, do you really think they have a competent it staff? When you have something stolen, the last thing most normal people think of is to check their computer data (first thing would be to check what they sole and who did it). Data loggers are quite easy to miss unless you specifically are looking for them. This is an exercise that tests both physical and data security into one heist.

      It is reasonable? Most criminal admittedly will do one or the other but there still exists the possiblity of both. This single tests in some ways covers all aspects though not completely.

      People in the real world just do not understand the importance of data. Also, data stolen does not directly affect the bank in question but rather it's customers. It's hardly surprising that such things are often missed. We should hold them up to a higher standard but reality is always far from ideal.

    2. Re:And I call by cusco · · Score: 5, Informative

      Not really. I work for a company that does physical security for businesses (key cards, alarm systems, cameras, etc.) Probably 70 percent of the time I could walk into a customer site, say "I'm Brian from Something-or-other Security", sit down at the guard's monitoring computer, and no one would stop me. Only once in five years has anyone called our office to make sure that we were really the guys they sent.

      Want to get into a secured location? Get yourself a fake badge and a jacket that says XYZ Security Installers on it. Walk up to a door about lunch time with a tool bag in one hand and a ladder in the other, maybe a box or two tucked under an arm. Make a show of not being quite able to get your badge to the reader without putting everything down. People are too polite, they'll not only badge the door for you but then they'll hold it. I've seen it happen plenty of times, we even did it for a customer's security director to show them that their people really did need training.

      --
      "Think about how stupid the average person is. Now, realise that half of them are dumber than that." - George Carlin
    3. Re:And I call by Dunbal · · Score: 4, Informative

      Yeah, except none of this happened. The guy is just presenting a different version of the a similar BS story he spat out in an interview with CNN in 2008. Except that time he walked out with a bunch of back up tapes. Of course now that he has been on TV, he's free to make up any bullshit he wants so long as suckers like you keep lapping it up. After all it's entertainment. But you are reading a "work of fiction" that is at least 3 years old.

      --
      Seven puppies were harmed during the making of this post.
    4. Re:And I call by Dunbal · · Score: 1

      That's not the part I object to. I agree it's possible to walk into somewhere. What I think is unreal is that the guys could go around picking up wallets, cell phones and laptops and walk out of the bank without anyone noticing anything and suspecting them - even if it's the next day. And once people realize that they have been robbed, usually they check a little more to see what else has gone missing or been tampered with. The guy makes it sound like he can do it all the time. I call BS. It's far more likely he's out pushing his book and his security company by making shit up.

      --
      Seven puppies were harmed during the making of this post.
    5. Re:And I call by wren337 · · Score: 2

      Try carrying a big costco sheet cake that says "Happy Birthday!". Easier than carrying all those tools, and you can go business casual.

    6. Re:And I call by skiingyac · · Score: 3, Interesting

      Once there was an actual criminal going around a large office park at a place where I previously worked that would walk in wearing a VERY fancy suit and kindof wander around stealing laptops, electronics, etc. and then walk out. Nobody could ever identify him except that he was in a fancy suit, and nobody dared question what he was doing so as not to get in trouble for offending somebody important. Not saying any of these places were supposed to be highly secure, but was quite a problem for a while and he always got out before anyone noticed or realized what was going on.

      Then he walked into our office which was a startup, and he was obviously not familiar with the "atmosphere". As soon as he got in by following behind somebody, several people said "What the **** are you wearing a suit for and what the **** are you doing here?", took a picture of him, and escorted him out.

    7. Re:And I call by dkleinsc · · Score: 4, Interesting

      A true story regarding the problem of walking in behind people (one of the easiest ways to enter a large building you shouldn't be able to access):

      Employee walks into the office building. A bit behind that employee was the CEO, but the CEO's badge was not visible, and this was a newer employee who didn't recognize the CEO. The employee made sure the door closed on the CEO. The CEO took swift action to send a message to the whole company: He called security, found out who that employee was, and sent word down the chain of command to give that employee a special award.

      --
      I am officially gone from /. Long live http://www.soylentnews.com/
    8. Re:And I call by ackthpt · · Score: 5, Insightful

      Once there was an actual criminal going around a large office park at a place where I previously worked that would walk in wearing a VERY fancy suit and kindof wander around stealing laptops, electronics, etc. and then walk out. Nobody could ever identify him except that he was in a fancy suit, and nobody dared question what he was doing so as not to get in trouble for offending somebody important. Not saying any of these places were supposed to be highly secure, but was quite a problem for a while and he always got out before anyone noticed or realized what was going on.

      Then he walked into our office which was a startup, and he was obviously not familiar with the "atmosphere". As soon as he got in by following behind somebody, several people said "What the **** are you wearing a suit for and what the **** are you doing here?", took a picture of him, and escorted him out.

      The lesson is: You can steal more with a suit and tie than you can with a gun.

      --

      A feeling of having made the same mistake before: Deja Foobar
    9. Re:And I call by Anonymous Coward · · Score: 0

      Robert Redford did this:
      "We're late for a party on the second floor. Push the goddamned buzzer."

    10. Re:And I call by Anonymous Coward · · Score: 0

      I hope that wasn't sarcastic.

    11. Re:And I call by NiteShaed · · Score: 2

      What I think is unreal is that the guys could go around picking up wallets, cell phones and laptops and walk out of the bank without anyone noticing anything and suspecting them - even if it's the next day.

      I don't think they were doing anything of the sort. They were testing security of company (bank) information, not just general security. I think by "grabbing everything" he was talking about things like USB sticks or disks, not wallets. It would be a stupid test if they took personal items as well, might as well just walk in wearing ski-masks.

      --
      Some bring out the best in others, some the worst. Some bring out far more.
    12. Re:And I call by karnal · · Score: 2

      A gate guard did this to our company's president on his first day. Same thing, appreciated that the job was done properly even if it inconvenienced him some.

      --
      Karnal
    13. Re:And I call by Kyont · · Score: 4, Interesting

      I totally second that. For me, it was a tie and a clipboard, and my (totally true and legit) story that I worked for the building's property insurance company and needed to look everywhere and anywhere for risks (blocked doors, covered sprinklers, stacks of live ammo pointed at compressed oxygen canisters, that sort of thing). People would let me into the most amazingly sensitive areas, oftentimes with no escort, just a slap on the back and a "give the key fob back to Tina when you're done". Three hours later I would know every corner of the place.

      I ain't that charismatic, so I conclude the clipboard is key.

      --
      You shall see a cow on the roof of a cotton house.
    14. Re:And I call by dkleinsc · · Score: 2

      It wasn't - the CEO actually did the right thing.

      And I should mention that the company in question here was a Fortune 1000 company, not some startup.

      --
      I am officially gone from /. Long live http://www.soylentnews.com/
    15. Re:And I call by MaXintosh · · Score: 1

      The clipboard is key. I've found the following pattern for having people leave me alone when I'm doing work out and about in outdoor places where people might (and sometimes should) ask me what the hell I'm doing there. An official looking hat works some of the time, and if people ask what I'm up to, I can point to it and say I work for them (even if I'm wearing a hat for a totally different organization). This seems to satisfy people. A clipboard works the majority of the time, although sometimes I have to wave it around and say I'm with XYZ organization. Any explanation, even a bad one, seems to work. An orange reflective safety vest has worked 100% of the time. It is the ultimate in human camouflage for walking around without question.

      Luckily, I actually belong in those places when I'm working. But I've often wondered what sort of trouble other folks could get up to without anyone noticing.

    16. Re:And I call by DavidTC · · Score: 1

      What's especially clever is if you actually spend time really taking notes on pointless things. Spend five minutes measuring the distance between electrical outlets or whatever.

      Even if you have an escort, they will quickly get bored.

      Bonus points if you actually forms on the clipboards with blanks on them that want that information.

      Incidentally...stacks of live ammo pointed at compressed oxygen canisters? Seriously?

      --
      If corporations are people, aren't stockholders guilty of slavery?
    17. Re:And I call by Leebert · · Score: 1

      For me, it was a butt set (http://en.wikipedia.org/wiki/Lineman%27s_handset) along with the clipboard.

      I did a fair amount of network cabling support years ago, mostly in retail locations. I'd be wandering around the stock room of a Best Buy or Wal Wart, someone would come up to me and ask: "Can I help you?", and I'd reply: "No, thanks; I'm good." They'd stand there uncomfortably for a second, and I'd walk away with a warbling toner. Always a blast.

    18. Re:And I call by dbIII · · Score: 1

      Overalls and a hard hat with the logo of an unrelated company have got me into two power stations, an oil refinery and a fertilizer works before I was authorised to enter. Possibly the main reason is the system in each place for allowing access was almost completely useless at each place - to be allowed in you had to get in and do a safety course inside the gate and once you were in the gate there was no more security. I had a valid reason to be there in each case but nobody told the security people so I could have been anyone.

    19. Re:And I call by Kyont · · Score: 1

      Incidentally...stacks of live ammo pointed at compressed oxygen canisters? Seriously?

      OK, it was rarely that bad, though I did see things like empty pallets stacked to within inches of the fire sprinklers, gas cans stored in unventilated stationery rooms, and plenty of other violations of common sense and/or the fire codes.

      There was a famous incident we studied in classes where a small fire started in a big warehouse (Kmart I believe). Or at least, it should have remained small and been quickly contained by fire sprinklers. But one of the pallets that caught on fire was a bunch of cans of some pressurized flammable aerosol thing, like WD-40 or hairspray or something. The heated cans exploded and became torches that skittered all over warehouse, lighting everything in their path on fire. Pretty soon the sprinklers were overwhelmed and a cool $100 million was up in smoke. So now, warehouses are required to keep pressurized flammables in a chain link cage so they can't shoot too far (but again, sometimes we'd find them just sitting out, ready for another War of 1812 re-enactment). Fun stuff.

      You are spot on about the measuring and the forms. People are busy, and can't take half their entire day just to watch you do paperwork. If you're in the South, just talk huntin' and fishin' for five minutes, and most warehouse guys will be ready to donate you a kidney.

      --
      You shall see a cow on the roof of a cotton house.
    20. Re:And I call by neminem · · Score: 1

      Didn't you read the second part of the thing you quoted? I'd say the real lesson is, "when attempting any sort of scam, study your marks first."

    21. Re:And I call by Semyazza · · Score: 1

      I did this once as a new employee and was terminated 2 weeks later.

  10. Cash on demand by 0123456 · · Score: 1

    Interestingly, I was watching an old movie from the 60s a few days ago where the crook convinces the bank staff that he's from their insurance company and come to the bank to check their security, then robs it.

    Similar ideas seem to have been around for a long time.

  11. Thieves on the outside, thieves from within by goffster · · Score: 1

    Here we are in between.

  12. If you want to rob a bank, become CEO. by bussdriver · · Score: 3, Insightful

    Surely recent years has shown the most successful bank robbers run banks.

    1. Re:If you want to rob a bank, become CEO. by EvilBudMan · · Score: 1

      It's always been that way we are just now figuring it out.

  13. Money by Anonymous Coward · · Score: 0

    So putting key loggers onto some computer is going to make you money how?

    1. Re:Money by History's+Coming+To · · Score: 2

      Really?

      PIN numbers, account numbers, sort codes, mother's maiden name, address....people type lots of interesting things into computers these days.

      --
      Please consider this account deleted, I just can't be bothered with the spam anymore.
  14. Not my job.... by David_Hart · · Score: 3, Interesting

    Physical security and access is not the job of the standard employee. The only job the employee has is to ensure that their credentials are only used for thier access, either physical or digital, and that they are kept secure.

    I once was working for a company that had higher a new CIO. The area where the IT people sit was secured with keycards, and was just outside of the server room, which had its own keycard. There was never any problem with letting visitors and other employees in and out to discuss IT projects, etc. In other words, while it had keycard access, it wasn't considered a security zone. The CIO came to visit the IT area and I let him in without knowing who he was. He was then buzzed into the Sever room by one of the operators who did know who he was. Of course, he made a big stink about the whole thing. The funny thing of course, is that nothing changed. He was just trying to make a big splash.

    The point is, I am not a security guard. I am not about to put my physical safety in jeopardy for the sake of corporate secrets. I do not have the necessary skills to vett or interrogate every new visitor wandering our halls, nor do I have the authority or tools to throw them out. You can chew out your employees for allowing physical access to this "fireman" but the problem is management not spending the money to have proper security at the door, not the lack of vigilance by the employees.

    I will keep my passwords secret, I will choose complex passwords, I will not allow people to tailgate on my keycard access, and I will inform IT security if any of my corporate devices goes missing. I will do all of this, but I will not be your security guard, there are people who do this who are much better at than I could ever be...

    1. Re:Not my job.... by Slider451 · · Score: 1

      The point is, I am not a security guard. I am not about to put my physical safety in jeopardy for the sake of corporate secrets. I do not have the necessary skills to vett or interrogate every new visitor wandering our halls, nor do I have the authority or tools to throw them out.

      I will keep my passwords secret, I will choose complex passwords, I will not allow people to tailgate on my keycard access, and I will inform IT security if any of my corporate devices goes missing. I will do all of this, but I will not be your security guard, there are people who do this who are much better at than I could ever be...

      You're close to fulfilling your responsibilities. Just add "challenge strangers to present valid credentials" and "report suspicious activity" to your list. You don't have to risk your physical safety to do those.

      --
      Nostalgia isn't what it used to be.
    2. Re:Not my job.... by afidel · · Score: 1

      The only problem I see is not that he was allowed in, it was that he was left without an escort. Only 10 people have access to our datacenter and all of them know that a) they should clear the person with me and b)they should not be left alone unless I specifically say so (some vendors technicians we are comfortable enough with to allow them unescorted, besides we have video monitoring of the datacenter). The same goes for the IDF closets. The only time we're really vulnerable is when an IDF closet has an AC unit go down, then we prop the door open as the cost/benefit didn't allow for redundant cooling in those rooms.

      --
      There are 4 boxes to use in the defense of liberty: soap, ballot, jury, ammo. Use in that order. Starting now.
    3. Re:Not my job.... by David_Hart · · Score: 1

      If management can't be bothered to hire enough security personnel to take care of this at the door, then they need to take responsibility for anyone who enters the facility without the proper credentials. This is a security job, not an employee responsibility.

      However, I do agree that an employees should report suspicious activity.

    4. Re:Not my job.... by David_Hart · · Score: 1

      But again, it was left up to employees, not security, to escort the "fire marshall". Employees should only escort people that they personally have business with. All others should be escorted by security, people who are trained to verify credentials, contain access, etc.

      Leaving this job to employees is an abdication the responsibility of security by management. It's a way of reducing costs while putting the responsibility on the average employee who doesn't have the right training to handle these situations. Of course, it's always the employee who gets blamed when these types of breaches occur, and not the management policy that was the root cause.

    5. Re:Not my job.... by afidel · · Score: 1

      We don't have security, a bank should, but most businesses do not. Hell, when I worked for Cisco, a defense contractor, neither of the offices I was responsible for had a security department. I mean as long as you escort any outside personel and observe what they are doing you should be good most of the time, I mean I'm more likely to spot a port scan or attempt to attach an access point than a security guard.

      --
      There are 4 boxes to use in the defense of liberty: soap, ballot, jury, ammo. Use in that order. Starting now.
    6. Re:Not my job.... by Anonymous Coward · · Score: 0

      i am not paid enough to care. care costs extra.

  15. Poor story. by Viewsonic · · Score: 1

    This story is working on too many assumptions that probably aren't true.

    An analogy would be a story about robbing Fort Knox but putting on a fake military uniform and saying you're an important general, and you want to look at the gold just to make sure it is all there.

    Seriously, THATS how bad this story is. IDs not checked? USB ports not disabled? What?

    1. Re:Poor story. by NiteShaed · · Score: 3, Interesting

      Completely plausible actually.

      IDs not checked?

      He does present ID. The fact is though that as long is it looks "official", most people will believe that it is what it says it is. Assuming you're not on your local fire department, do you know what your town's fire-inspector's ID actually looks like? It's not like this guy was handing them a piece of notebook paper with "Fire Inspekter" written on it in crayon.

      USB ports not disabled?

      Plenty of computers use USB keyboards, so there's your enabled port. A keylogger plugs into the port, the keyboard plugs into the keylogger, and done. Same thing went for the old PS/2 ports. Even if your average bank employee looked at the back of their PC (which isn't very likely to begin with), they probably wouldn't recognize anything out of the ordinary.

      --
      Some bring out the best in others, some the worst. Some bring out far more.
    2. Re:Poor story. by Anonymous Coward · · Score: 0

      An analogy would be a story about robbing Fort Knox but putting on a fake military uniform and saying you're an important general, and you want to look at the gold just to make sure it is all there.

      Seriously, THATS how bad this story is. IDs not checked? USB ports not disabled? What?

      http://en.wikipedia.org/wiki/Wilhelm_Voigt#Captain_of_K.C3.B6penick

    3. Re:Poor story. by Culture20 · · Score: 1

      An analogy would be a story about robbing Fort Knox but putting on a fake military uniform and saying you're an important general, and you want to look at the gold just to make sure it is all there.

      Closer to pretending you're a traffic cop on a street directing people only in one direction. Authority, but not *too* much authority. The best part about the Fire Inspector is that he doesn't prevent anyone from doing their jobs (the job of the guards in your example are "don't let anyone past unless they're fully authorized (and random general isn't)".

      Seriously, THATS how bad this story is. IDs not checked? USB ports not disabled? What?

      Bank branches aren't the CIA. IDs don't get checked. USB ports most assuredly are not disabled, and I bet the desktop HDDs aren't encrypted either.

    4. Re:Poor story. by Anonymous Coward · · Score: 0

      This story is working on too many assumptions

      ......

      that probably aren't true

      this is probably an assumption, but you probably make too many assumptions..

  16. Hey guys... by Anonymous Coward · · Score: 0

    ...wallet inspector.

    1. Re:Hey guys... by Joe_Dragon · · Score: 1

      I can't believe that worked

    2. Re:Hey guys... by Anonymous Coward · · Score: 0

      again...

  17. "Bank"? by MrEricSir · · Score: 1

    Most of the companies called banks nowdays have about as much to do with banking as going down to Vegas and putting all your money into a slot machine.

    Banking is relatively low-risk; creating "financial instruments" and selling them is potentially high risk, unregulated, and untested.

    So don't call it banking.

    --
    There's no -1 for "I don't get it."
  18. Classic trick by Anonymous Coward · · Score: 0

    I remember an article from a few years ago where I man would wear a white shirt with a tie, and black pants and just walked into this one office every week for months and just took computers and walked out. Nobody questioned him at all because he looked like anyone else working there so they had no suspicions. The only reason they found out about him was the security footage of him coming and going at random times.

    1. Re:Classic trick by EETech1 · · Score: 1

      where I man???

      Was it you?:)

  19. Re:Small time...Big Time was Congress by BoRegardless · · Score: 1, Insightful

    But the group that sets the rules TELLS THE BANKS what they will do.

    CRA, The Community Reinvestment Act demanded that banks make loans to low income areas regardless of meeting loan requirements or...the banks would be subject to having their approval to be a bank revoked by the Treasury Dept. or whoever oversaw the CRA.

    The banks made the loans but said "We can't keep these marginal loans" so all the biggies agreed that FMae and FMac would take them...but then they said they couldn't hold them, so rules were made to allow them to sell into "mortgage pool securities".

    The whole damned thing was pushed by the U.S. Congress.

  20. Comment removed by account_deleted · · Score: 1

    Comment removed based on user account deletion

  21. Full article by Hentes · · Score: 1

    Here is a link to the printable version.

  22. Re:Small time...Big Time was Congress by Anonymous Coward · · Score: 1

    But the group that sets the rules TELLS THE BANKS what they will do.

    Not really, although that's what they teach you in schools. In reality, congress asks the financial industry lobbyists what laws they want and has the lobbyists write the legislation. The congressman sponsoring the legislation writes very little of it (if any) and probably doesn't even read it all. That's why laws like exceptions to capital requirements for large banks (Bearn Sterns or bigger) are passed - look it up. That's the rule now, not the exception.

    CRA, The Community Reinvestment Act demanded that banks make loans to low income areas regardless of meeting loan requirements

    This has next to nothing to do with the financial crisis, as many financial insiders (like the old Lehman Brother's CEO and others) have discussed. Those loans were extremely profitable to the banks and in any case, it has nothing to do with the housing bubble in Spain, Ireland, China, etc... There are many rebuttals to this position online.

  23. security? by Anonymous Coward · · Score: 1

    back 8 years or so ago, a guy who was installing security cameras in a bank called. I never met him before or knew who he was, he just knew of me through a friend. He wanted me to come setup the network on the cameras to work with the banks network. So I show up and spend the next couple hours in the back room of the bank with the servers, totally un monitored and un supervised, and after hours setting up the cameras. No one at the bank asked for my id or even my name, and one person asked if I would look at their laptop quick...

  24. Here's How I Do It... by Greyfox · · Score: 1
    --

    I'm trying to teach myself to set people on fire with my mind... Is it hot in here?

  25. You want an effective security system? by Beeftopia · · Score: 2

    Then don't create a system where employees are forced to question someone who might be the company CEO or a senior VP.

    This is the core issue - security systems are set up where "playing it safe" for the employees means looking the other way.

    The solution? Get rid of card reader-only secured doors. You need vertical turnstiles which ONLY allow one person through, and signs which clearly say that if you let someone through, YOU will be fired for that.

  26. Re:Small time...Big Time was Congress by stdarg · · Score: 1

    This has next to nothing to do with the financial crisis, as many financial insiders (like the old Lehman Brother's CEO and others) have discussed.

    How do they know? Because they're insiders? There's so much misinformation and genuine complexity that it's almost impossible to say. However, look at this little tidbit in an article about Capital One's plans to buy ING Direct: http://dealbook.nytimes.com/2011/08/23/in-feds-move-on-capital-one-deal-a-test-of-dodd-frank/

    Clarity, if not an answer, may have come inadvertently from National Community. The coalition argues that Capital One’s application to acquire ING Direct is suspect because Capital One refuses to lower its credit standards to extend Federal Housing Administration-insured loans to people with credit scores of 580. This is the lowest credit score allowed by the F.H.A. National Community contends that this is discriminatory against members of minority groups because they tend to have lower credit scores and have been hit harder by the financial crisis.

    Capital One has responded by agreeing to lower its credit score requirements by 2012. For National Community, this is not enough, because Capital One’s F.H.A. loan volume is relatively flat in growth. Capital One is now a bit player with less than 1 percent of the F.H.A. loan market. National Community wants the combined entity to make more of these loans, since they help people who could not otherwise afford a mortgage.

    Who is National Community? (http://www.ncrc.org/)

    In recent years, NCRC has led efforts to reform the financial system, respond to the foreclosure crisis, and expand the Community Reinvestment Act. We are experts on banking, business development, community reinvestment, community development, civil rights, housing, and workforce issues.

    I love the idea of "inadvertent clarity" here -- it's funny but absolutely true. This organization is working with the government to make banks, today, right now, take on more risk and make more loans to poor people, and fight legitimate business deals that reduce risk. They don't go out of their way to advertise the role they play in adding risk to the financial system, of course, but the fact that it was slipped into this rather dry article is awesome. You really don't see that happen in the NY Times too much.

    You're claiming "Those loans were extremely profitable to the banks" -- I'm curious if the excerpt I posted makes you change your mind on that.

    And you also claim "and in any case, it has nothing to do with the housing bubble in Spain, Ireland, China, etc" but surely you see how the largest market in the world (the US) has an affect on international banks (e.g. ING Direct is owned by a Dutch conglomerate).