A lot of hacking is actually social engineering. It's not hard to get a tech-illiterate person to give up their password, and that's the softest target for an attack.
post
Hacker voice: "I'm in"
Looks at overly complicated industry software he's never even heard of before
"I'm out"
"Looks like these guys have already been hit with ransomware."
Wait, I have an idea! Yes, just as I thought, I can overlay their proprietary operating system with this fancy looking graphical interface that resembles nothing and gain full control of their system. I'm back in!
That sounds like Grafana with extra steps.
I was thinking of the James Bond movies where they show hacking to be a guy wearing glasses looking for a glowing ball in a flashing GUI that he rotates around somehow by typing really fast.
We have these obligatory online seminars about web security /privacy at work.
Turns out that for some reason, with Privacy Badger enabled, they appear as "passed" instantly. I never saw a single second of these endless seminars.
I tried to tell the IT guy but he couldn't care less and I suspect he didn't even know what Privacy Badger actually is
Or maybe he feels that these seminars are for people who don't use things like privacy badger.
Its like the only accurate part of hackers
We get fake phishing emails that are actually from IT and if we don't recognize and report them, we get a talking-to. It's a good way of keeping employees vigilant.
A friend (who actually works in IT) apparently has a good system at his company. It actually automates turning real phishing attempts into internal tests. It effectively replaces links etc and sends it onwards. If the user actually clicks through, their account is immediately locked. It requires them to contact IT to unlock it again, often accompanied by additional training.
My last company did this. They'd also send out surveys and training from addresses I didn't recognize, so I'd report those, too, only to be told they were legit π
I send supervisor emails about stuff I'm not gonna do to my spam folder as well.....
"Did you get the email?"
"Nope, sorry, it looked a little suspicious so I didn't open and sent it to spam.."
(Opens DOS, frantically types)
βHeh. I was able to SSH right into their jpg with nothing but an Ethernet cable and router grease.β
Nah, this isn't cool. Fuck the company, but this will fuck over the users more than anyone.
"I wonder why they'd need my 2FA too, but oh, well... "
You get a duo push! And you get a duo push! ...
I might care if they paid me a living wage.
Iβm all for acting your wage, but I donβt want to make victims of anyone who is interacting with my company simply because I was feeling spiteful. The company will be fine, the tons of people who just had their information leaked are the ones who are truly inconvenienced and may face financial repercussions later on when their information is distributed. Just something to consider
A good portion of the movie Hackers was social engineering. That's how Mitnick got into a lot of systems as well. Why search for vulnerabilities in apps when people are much easier to manipulate.
I wonder if that's how my old job had 780 gb of source stolen though social engineering.
780 gb of source code? Sounds a bit overengineered, I bet that was hard to audit for security flaws
Pay people enough and this is less likely to happen.
top 50 comments