We have repeated it to the point of exhaustion: people—users—are the weakest link in the security chain that can keep our private data safe. Social engineering relies on this axiom of computer security to craftily and almost imperceptibly extract useful information from us for its projects without us even noticing. In this article, we review the concept of social engineering as a hacker tool, its characteristics, why it is so effective, and some precautions to avoid being deceived by these artisans of espionage and psychological hacking.
What Is Social Engineering and How Does It Work?
In a few words, social engineering (SE) is a set of psychological techniques and social skills—such as influence, persuasion, and suggestion—applied directly or indirectly to a user to get them to reveal sensitive information or useful data without being aware of its eventual malicious use. These can be carried out through technology and computers or directly through personal interaction. The goal is to bypass or make it easier to access traditional security systems by obtaining information from the most trusted but most vulnerable source: the very person being protected.
https://old.neoteo.com/los-mejores-administradores-de-contrasenas/Two Kinds of Social Engineering and an Internal Debate
As a way of separating them, two types of social engineering are often discussed. One, called computer-based SE, involves taking advantage of the mistakes users make when falling for email chains, hoaxes, spam, pop-up windows, and infected messages. This label, personally (and most of the SE community agrees), does not represent the classic, conceptual social engineering—the human-based one, which is based on human resources and on dealing, generally directly (even if via a computer), with the victim's data.
This is a matter of purism regarding the craft of the work and a repulsion for the automated, computer-based modes (mass and serial collection of data via spyware, Trojans, etc.), but every technique has its internal debates, and this is one of them with my position on it.
That said, the social engineering we're dealing with here is the human-based one, which, given its properties and its independence from large-scale technology, can be used—as one SE professor used to say—both to coax a few exam answers out of someone and to obtain the access code to a private financial firm's network.
https://old.neoteo.com/dentro-de-un-centro-de-llamadas-de-estafas-fraude/Psychology as the Main Tool
Using human psychological traits like curiosity (what moves us to look, answer, and touch where we shouldn't), fear (when we're afraid, we seek help by any means or fall more easily into traps because we can't reason calmly), and trust (we feel safe at the slightest show of authority), social engineering is the art of exploiting intentional circumstances—but also, and quite often, accidental ones.
That's why experts stay alert to any mistake you make without noticing. Part of social engineering's effectiveness lies here, because what you say in front of anyone you meet might seem irrelevant, but to a cracker using this method, the name of your cousin or the high school you attended could become the key to your email—and from there, to the rest of your financial services, for example.
Methods and Techniques of Social Engineering
Passive Techniques
These can be the passive techniques, which are based simply (though that doesn't mean easily) on observing the person's actions. The main thing in SE is that each case is different, and therefore each expert's development is tied to the environment, nature, and context in which the information to be obtained moves. That is, they have to adapt. For this, the first step is observation, which includes forming a tentative psychological profile of the person to be approached, learning their computing habits, gathering simple data like birthdays, family names, etc. Anything helps, and you'll see when we discuss a case later.
Remote Techniques
Other techniques are remote, where communication channels like letters, IRC, email, phone, and others are used to obtain useful information according to the case. These are the most common and the ones that show the most success cases (for crackers, obviously), because people tend to over-trust data after seeing a well-written text with an emblem, seal, or signature that gives it false legitimacy.
In-Person Non-Aggressive Techniques
In-person non-aggressive techniques include following people, surveillance of homes, entering buildings, accessing agendas, and dumpster diving (looking for information such as sticky notes, bills, receipts, bank statements, etc. in the target's trash).
Aggressive Techniques
In the so-called aggressive methods, the experts' work becomes more intense, and that's where identity theft emerges (posing as IT, technical services, security personnel, etc.), depersonalization, and the most effective psychological pressure. According to security experts, combining this last group of techniques with the exploitation of the three psychological factors mentioned above on the victim can be highly effective in face-to-face work between victim and victimizer.
https://old.neoteo.com/como-usar-wifislax-como-averiguar-la-contrasena-de-una-red-wifi/A Social Engineering Case in Phases
The first phase of a piece of craft social engineering involves an approach to build trust with the user. This is achieved through emails posing as technical representatives of some service, or even through a formal introduction in a casual conversation, showing empathy and easing the potential alertness toward the stranger (though it could be a coworker, a friend of an acquaintance, etc.). The attention they pay during this stage is essential to capture any information we say and take it as valuable.
What follows that basic data collection is generating a concern, interest, or need in the other person. Based on their curiosity or desire, they will be consciously and unconsciously predisposed to provide information. The expert's idea is to observe our reaction and act accordingly with a slightly more aggressive technique if the data to be obtained has a high level of protection. The rest is trial and error, depending on the case at hand.
For example, if an investigator simply wants to find a way into your email, they might only need to know you have a blog where you write personal things, extract names of relatives, institutions, and important events from your life, and then “run” to your email login and ask to reset the password because they've forgotten it. If you happened to set the security question as “What is my best childhood friend?”, the expert is probably laughing their head off and already inside your inbox with information you gave them yourself.
If they don't succeed that way, the work isn't over—they'll look for more aggressive techniques or repeat the process to gather new information. All of this, I repeat, is tied to the case we're referring to. If a cracker is trying to take down a state's computer system, they obviously won't go read the personal blogs of the cleaning staff.
The Effectiveness of Social Engineering
As the famous phreaker and hacker Kevin Mitnick says, social engineering has four principles that make its effectiveness as a hacker tool immeasurable. The first is that when someone inspires the slightest respect or even pity, “We all want to help.” So we always show ourselves willing to give a little more than asked.
That leads to the second principle, “The first move is always trust toward the other.” The third principle exploited by SE experts is that “We don't like saying NO.” This makes us less reluctant to hide information and question whether we're being too paranoid by denying everything and how that will affect the other person's view of us. The last point is indisputable: “We all like to be praised.” .
If you know Dale Carnegie and his best-seller “How to Win Friends and Influence People”, you'll know what he means. With these sociological principles applied along with the SE techniques mentioned above on an individual who shows vulnerability through ignorance, carelessness, or inexperience, the social engineers' work becomes not only effective but also undetectable, since they generally leave no useful traces for investigations.
https://old.neoteo.com/persiguiendo-mi-estafador-8-lecciones-para-caer/Knowing How It Works Is Knowing How to Defend Against It
Because of its characteristics and because its main tool is adapting to different scenarios and personalities, social engineering is one of the most difficult techniques to avoid, and it's undetectable or questionable since it handles aspects of psychology that couldn't be brought to evidence factually. What you can do is exactly what you've done: read about how it works and stay alert to different intentions without becoming paranoid or anything like that.
Generally, people are good and have good intentions—or at least I want to die believing that. But don't let that blind you from taking precautions, like not having people nearby when you enter a password, being smarter with your passwords and especially with the way you recover them if you lose them. Don't write down passwords, access codes, or sensitive information on paper that could be thrown away intentionally or accidentally. Trust whom you need to trust, and stay alert to the intentions of those who try to help you through dangerous means.
Also remember—and this is studied—that two or three solid arguments are always better than fifteen. Don't open emails from strangers, and no, you will never, ever win a car just for having a phone and sending your personal ID through it. Also remember that a quick search on any search engine can often let you know whether an email, an offer, or a technical suggestion is dangerous.
Epilogue
That's all for this humble report on what I know and can tell about social engineering as a hacker tool, but also as a tool for everyday life, since suffering its consequences doesn't require having a computer in the mix. Don't be paranoid; be more attentive and stay informed, remembering once again that the most vulnerable link in any security system is ourselves.