Social Engineering for Everyday (Startup) Life - Extended

Post on 14-Jan-2015

279 views 0 download

Tags:

description

Social Media Week Berlin talk from Sept. 23, 2013. Want to learn more about the dark art of social engineering? Wish you could peek behind the curtain and get a look at how hackers and mentalists seem to be one step ahead of the rest of us? Wondering how you could be like them? This talk dispels the myth and mystery of social engineering and explains how you can actually start doing it yourself. We start by looking at its history and building a basic knowledge of the core principles of this sly art. Then, we explore the social engineer’s toolkit and walk through a concrete example to unpack the 5 steps to engineering a tricky situation we all encounter at work. Finally, we wrap up by pinpointing what it takes to succeed as a social engineer and reviewing some take-home assignments everyone can try. And for those who know that you’re either playing the game or being played, I welcomed challenges during the Q&A.

Transcript of Social Engineering for Everyday (Startup) Life - Extended

@deadroxy

Social Engineeringfor Everyday (Startup) Life

Johanna Brewerfrestyl Co-Founder

Doctor of Computers

@deadroxy

What is Social Engineering?

@deadroxy

No Computers Needed

@deadroxy

Social Engineering != Hacking

@deadroxy

@deadroxy

Social Engineering == Inception?

Shane

@deadroxy

Social Engineering == Stealing?

@deadroxy

Social EngineeringThe art of crafting a social situation in which the actors

are more likely to follow the engineer’s desired path.

Not Magical

Not

@deadroxy

@deadroxy

“freestyle is the best live music discovery app ever!”

#fail

–Some Blog

@deadroxy

From: Megan (megan@frestyl.com)To: Some Blog (blogger@someblog.com)

Subject: Correction to your blog post

You misspelled our company name in your blog post. The correct spelling is: frestyl. Please update it.

@deadroxy

From: Megan (megan@frestyl.com)To: Some Blog (blogger@someblog.com)

Subject: Thanks! (and small correction to your blog post)

Hi Blogger,Thanks so much for the post!!

Just a quick favor... I noticed “frestyl” was spelled incorrectly. Do you think you could update it? Thanks so much!

@deadroxy

From: Megan (megan@frestyl.com)To: Some Blog (blogger@someblog.com)

Subject: ???

...These aren’t the droids you’re looking for...

@deadroxy

1. Review Your Resources2. Pick a Principle3. Create a Context4. Sign Post the Path5. Press Play

@deadroxy

What resources did Megan have?

@deadroxy

Hmm.

@deadroxy

1. Review Your Resources2. Pick a Principle3. Create a Context4. Sign Post the Path5. Press Play

@deadroxy

6 Key Principles of Influence

@deadroxy

Reciprocitypeople tend to return favors

@deadroxy

Commitment & Consistencypeople who commit (orally/in writing)are likely to honor their commitment

@deadroxy

Social Proofpeople do things they see other people doing

@deadroxy

Authoritypeople tend to obey authority figures

@deadroxy

Likingpeople are easily persuaded by people they like

@deadroxy

Scarcityperceived scarcity will generate demand

@deadroxy

The Hidden Principles...shh!

@deadroxy

Following & Flowingpeople tend to take the path of least resistance

@deadroxy

Self-Satisfactionpeople love to feel good about themselves

@deadroxy

1. Review Your Resources2. Pick a Principle3. Create a Context4. Sign Post the Path5. Press Play

@deadroxy

(non)AuthorityReciprocity

Self-Satisfaction

@deadroxy

1. Review Your Resources2. Pick a Principle3. Create a Context4. Sign Post the Path5. Press Play

@deadroxy

1. Review Your Resources2. Pick a Principle3. Create a Context4. Sign Post the Path5. Press Play

@deadroxy

From: Megan (megan@frestyl.com)To: Some Blog (blogger@someblog.com)

Subject: Thanks + BIG favor to ask

Hi Blogger,Thanks so much for the post! I shared it on all our social media channels and we are getting lots of likes + retweets!...

The set up.

@deadroxy

...

I have a real huge favor to ask though. I made a big mistake. I’m a new communications intern at frestyl, and when I sent you our info I must have spelled the company name wrong.

Totally not true.

@deadroxy

...

My boss made a big deal about getting our branding right when I contact press, and I obviously screwed that up completely.

Everyone hates their boss.

@deadroxy

...

If there’s ANY way you could make the correction for me in your post, it would be a HUGE help.

The effortless save.

@deadroxy

1. Review Your Resources2. Pick a Principle3. Create a Context4. Sign Post the Path5. Press Play

@deadroxy

...

I’m just hoping my boss hasn’t checked her Facebook yet.

Thank you again sooo much!!

The Kill.

@deadroxy

Everybody Feels Like a Winner

@deadroxy

Is SE just a big con?

@deadroxy

@deadroxy

#1: Do no harm; do some good

@deadroxy

#2: It’s just a game

@deadroxy

#3: Make believe like you mean it

@deadroxy

#4: Practice, practice, practice

@deadroxy

You’re either playing the gameor you’re being played

@deadroxy

Social Engineeringfor Everyday (Startup) Life

Questions? Challenges?