top 50 comments

sorted by: hot top controversial new old
[–] 133 points 2 years ago* (4 children)

A lot of hacking is actually social engineering. It's not hard to get a tech-illiterate person to give up their password, and that's the softest target for an attack.

  • source
  • hideshow 8 child comments
  • [–] 59 points 2 years ago (1 child)

    I prefer the old β€œdrop a usb in the parking lot”

  • source
  • parent
  • hideshow 2 child comments
  • [–] [S] 42 points 2 years ago (5 children)

    Be sure to put a label on it that says "secrets!"

  • source
  • parent
  • hideshow 9 child comments
  • load more comments (1 reply)
  • [–] 22 points 2 years ago (3 children)

    Or even jaded tech savvy people. I work in IT and there have been a number of times that I have witnessed or heard about people who know better causing an incident because they're burnt out or irate.

  • source
  • parent
  • hideshow 5 child comments
  • load more comments (1 reply)
  • [–] 12 points 2 years ago (5 children)

    That's a good point! I like the way you think! What is your password?

  • source
  • parent
  • hideshow 7 child comments
  • load more comments (3 replies)
  • [–] 98 points 2 years ago (2 children)

    Hacker voice: "I'm in"

    Looks at overly complicated industry software he's never even heard of before

    "I'm out"

  • source
  • hideshow 4 child comments
  • [–] 13 points 2 years ago (1 child)

    Wait, I have an idea! Yes, just as I thought, I can overlay their proprietary operating system with this fancy looking graphical interface that resembles nothing and gain full control of their system. I'm back in!

  • source
  • parent
  • hideshow 2 child comments
  • [–] 75 points 2 years ago* (5 children)

    We have these obligatory online seminars about web security /privacy at work.

    Turns out that for some reason, with Privacy Badger enabled, they appear as "passed" instantly. I never saw a single second of these endless seminars.

    I tried to tell the IT guy but he couldn't care less and I suspect he didn't even know what Privacy Badger actually is

  • source
  • hideshow 8 child comments
  • load more comments (2 replies)
    [–] 54 points 2 years ago (3 children)

    Its like the only accurate part of hackers

  • source
  • hideshow 3 child comments
  • load more comments (3 replies)
    [–] 45 points 2 years ago (15 children)

    We get fake phishing emails that are actually from IT and if we don't recognize and report them, we get a talking-to. It's a good way of keeping employees vigilant.

  • source
  • hideshow 18 child comments
  • [–] 36 points 2 years ago (5 children)

    A friend (who actually works in IT) apparently has a good system at his company. It actually automates turning real phishing attempts into internal tests. It effectively replaces links etc and sends it onwards. If the user actually clicks through, their account is immediately locked. It requires them to contact IT to unlock it again, often accompanied by additional training.

  • source
  • parent
  • hideshow 5 child comments
  • load more comments (5 replies)
  • load more comments (12 replies)
    [–] 45 points 2 years ago (1 child)

    (Opens DOS, frantically types)
    β€œHeh. I was able to SSH right into their jpg with nothing but an Ethernet cable and router grease.”

  • source
  • hideshow 2 child comments
  • [–] 35 points 2 years ago (1 child)

    Nah, this isn't cool. Fuck the company, but this will fuck over the users more than anyone.

  • source
  • hideshow 2 child comments
  • [–] 26 points 2 years ago (1 child)

    "I wonder why they'd need my 2FA too, but oh, well... "

  • source
  • hideshow 2 child comments
  • [–] 23 points 2 years ago (2 children)

    I might care if they paid me a living wage.

  • source
  • hideshow 3 child comments
  • [–] 33 points 2 years ago

    I’m all for acting your wage, but I don’t want to make victims of anyone who is interacting with my company simply because I was feeling spiteful. The company will be fine, the tons of people who just had their information leaked are the ones who are truly inconvenienced and may face financial repercussions later on when their information is distributed. Just something to consider

  • source
  • parent
  • load more comments (1 reply)
    [–] 16 points 2 years ago (2 children)

    A good portion of the movie Hackers was social engineering. That's how Mitnick got into a lot of systems as well. Why search for vulnerabilities in apps when people are much easier to manipulate.

  • source
  • hideshow 3 child comments
  • load more comments (1 reply)
    [–] 12 points 2 years ago (1 child)

    I wonder if that's how my old job had 780 gb of source stolen though social engineering.

  • source
  • hideshow 2 child comments
  • [–] 7 points 2 years ago (1 child)

    Pay people enough and this is less likely to happen.

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    load more comments
    view more: next β€Ί