Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

She did great on that social engineering attack. The crying baby on YouTube was a nice touch. The overall segment illustrates many aspects of psychological manipulation that can be used to successfully con a support person. A believable scenario, something people might sympathize with, a sense of urgency, further but brief engagement with questions/answers, and gratitude for their participation.

This stuff was always tricky to train people to defend against. I need to update my links to good presentations on this subject for attack and especially defensive training for employees. So, what do you people have to go in that collection?

Note: OP video led to autoplay of No Tech Hacking by Johnny Long. I recall someone recommending me read the book by same name. So, nice accidental reminder.

https://www.youtube.com/watch?v=N4kfsxF8Tio

Note 2: Bejtlich's comment on NTH on Amazon reminded me that we should probably always list Mitnick's Art of Deception and Abignale's Art of the Steal in these threads for useful examples they had. They each extracted much mileage out of social engineering.



> A believable scenario, something people might sympathize with, a sense of urgency, further but brief engagement with questions/answers, and gratitude for their participation.

Yep, pretty much nailed it right there. I think the fact that she acted surprised/confused at some of the security policies, rather than getting aggressive, helped sell her as a real customer that just needed some help.

I mean, not that real customers aren't assholes sometimes. It's just less likely that customer support will want to help them.


Ugh, so this is why banks ask you to type your cart number and call support password before they connect you to a real person. And then he asks you your some private informations, then fills them on the program, only after this he can give you a support.


Usually. It's also why some institutions will lock you out entirely without a visit for a photo ID check. Pre-designated people in some high-security settings with optional tokens or biometrics.

Now, some measures you run into will exist because a non-security expert formulated them to cover their ass after reading something online or in a bookstore. Or by security people who also have to comply with a policy or regulation of varying degrees of sanity. So, it's not always a real attack or risk inspiring specific measures but often is for verification during support.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: