Confessions of a Social Engineer

Working at the dangerous intersection of technology and security, social engineers help organizations stay safe(r) by exposing their vulnerabilities. Often, this relies less on advanced coding skills than it does on old-fashioned behavioral psychology and the reflexes of a trickster. In this humorous account, an infosec con artist spills her secrets.


“How I Socially Engineer Myself Into High-Security Facilities”
By Sophie Daniel
Vice
October 20, 2017

Hello! My name is Sophie and I break into buildings. I get paid to think like a criminal.

Organizations hire me to evaluate their security, which I do by seeing if I can bypass it. During tests I get to do some lockpicking, climb over walls or hop barbed wire fences. I get to go dumpster diving and play with all sorts of cool gadgets that Q would be proud of.

But usually, I use what is called social engineering to convince the employees to let me in. Sometimes I use email or phone calls to pretend to be someone I am not. Most often I get to approach people in-person and give them the confidence to let me in.

My frequently asked questions include:
What break-in are you most proud of?
What have you done for a test that you were the most ashamed of?

What follows is the answer to both of these questions. Read more.


The Library Pranksters Who Paid a Heavy Fine

These men pranked their local library. Homophobic outrage ensued. A bitter look back at a time of high stakes for creative pranksters.


“The Strange, Sad Story of Joe Orton, His Lover, and 72 Stolen Library Books”
by Natasha Frost
Atlas Obscura
August 9, 2017

A search warrant might seem excessive for library book hoarding””but Halliwell and Orton were no ordinary library pilferers. For over two years, Orton and Halliwell had been smuggling books out of their local libraries, the magnificent Art Nouveau Islington Central Library on London”™s Holloway Road and nearby red-brick Essex Road Library””and then returning them.

Orton hid books in a satchel; Halliwell, six-and-a-half years older, used a gas mask case. They would take them home, redo their covers and dust-jackets, and then slip them back onto the shelves.

Sometimes, these alterations were obscene: a reader scanning a relatively tame Dorothy Sayers whodunit would find themselves confronted with a mystery even before they opened the book. The blurb now described some missing knickers and a seven-inch phallus, and concluded: “READ THIS BEHIND CLOSED DOORS! And have a good s*** while you are reading!” Meanwhile, the collected plays of Emlyn Williams, a Welsh dramatist, suddenly included “Knickers Must Fall,” “Olivia Prude,” “Up The Front,” and “Up The Back.” Read more.


Alex Chang Plumbs the Depths of Telemarketing Scammers

A scambaiting expedition leads to an unexpected conclusion:


aotp_office
“I trolled my IRS scammers for weeks. I learned something really dark.”
by Alex Chang
Vox
October 18, 2016

These scammers had called me so many times that I knew their script.

They always introduced themselves as IRS officers with inconspicuous American names, like “Paul Thomas.” They called to collect the $6,000 I owed the IRS. And if I didn’t pay, they threatened to send the local police to arrest me.

They were unconvincing. I didn’t understand how this scam could work on anyone. But a quick search led me to a couple in Tennessee, a student in Virginia, and thousands of others who’d fallen for the scam. There was something about this scam that worked “” and I had to find out what it was.

So I got further and further into the scam. At first, I played along for a few minutes and then hung up. After a few days, I trolled them with the vast amount I learned about their operation. Then, on a hot mid-September day, I decided enough was enough.

I was going to get to the end of this scam.

That’s how I ended up talking to “Steve Smith” for 30 minutes. He was a senior investigations officer “” the actual person who walks you through how to send them money. I learned that his secret is maintaining an aura of authority. That’s how he optimizes fear. That’s how he gets people to suspend logic, drive to Walgreens, and buy iTunes gift cards to pay the IRS. The scam takes advantage of the most vulnerable people. Read more.


The Best Trick Wins the War

Infaltable decoys come of age with military sleight of hand. [Thanks Peter M.]


“A New Weapon In Russia’s Arsenal – And It’s Inflatable”
by Andrew E. Kramer
October 12, 2016
The New York Times

russianmilitarydecoysDeep in the Russian countryside, the grass sways in a late-summer breeze. In the distance, the sun glistens off the golden spires of a village church. It is, to all appearances, a typically Russian scene of imperturbable rural tranquillity.

Until a sleek MIG-31 fighter jet suddenly appears in a field, its muscular, stubby wings spreading to reveal their trademark red star insignia. A few moments later, a missile launcher pops up beside it.

Cars on a nearby road pull over, the drivers gaping in amazement at what appear to be fearsome weapons, encountered so unexpectedly in this serene spot. And then, as quickly as they appeared, the jet and missile launcher vanish.

“If you study the major battles of history, you see that trickery wins every time,” Aleksei A. Komarov, the military engineer in charge of this sleight of hand, said with a sly smile. “Nobody ever wins honestly.” Read more.


Long May Your Refrigerator Run

Gadgetary advances be damned, phone pranks endure in both old- and new-school iterations and seem to be intertwined with the human drive to communicate.

The Atlantic publishes a thinkpiece on the history and uncertain future of the artform.


“Do People Still Make Prank Phone Calls?”
By Julie Beck
The Atlantic
April 1, 2016

phonepranksOnly a rube or possibly an alien would pick up an unknown phone call, hear the question “Is your refrigerator running?” and answer in the affirmative. And so only the luckiest of amateur mischief-makers would get the satisfaction of getting to drop the “Well, you better go catch it!” before cackling away into the sunset.

And yet, amazingly, this doesn”™t seem to be the oldest trick in the book when it comes to telephone pranks. In her 1976 paper “Telephone Pranks: A Thriving Pastime,” Trudier Harris reports that people “over 50 years old” remembered the old refrigerator gag, which, if they pulled it as teens, means it could”™ve been around in the 1930s or earlier.

But other corny jokes were also around before the “˜30s, according to another paper, ones like:

“This is May.”
“May who?”
“May-onnaise.”

Most middle-class families had home phones by the 1920s or so, according to Claude Fischer, a professor of sociology at the University of California, Berkeley. And in the early days of the residential telephone, it was taken very seriously, as a tool for serious business, and so “children could trick unsuspecting adults fairly easily,” writes Marilyn Jorgensen in her paper “A Social-Interactional Analysis of Phone Pranks.” Read more.