5 ms·
IMHO tricking an employee to provide a login token is a con, not a hack.
by ConcernedCoder 5y ago
IMHO tricking an employee to provide a login token is a con, not a hack.
- ssully 5y agoIt's social engineering, which is definitely a hack/technique used in hacking.
- hpoe 5y agoActually I am with the parent on this one. We call it "social engineering" because it sounds cool, but I think that issue muddies the waters for the lay people. When people hear "hackers used Slack to break into EA games" they think something from the movies with some people in a dark room sitting around a screen and say "I'm in" in a deep voice. This convinces people hackers are prevaisve, unseen, and wield Godlike powers, clearly something they can't comprehend or do anything about, so no changes needed in their day to day life. In comparison if you were to phrase it as "some employees got conned into giving out their login info" that changes it to, "wow look at these guys, everyone knows you shouldn't give out your password morons." then the next time they need to give out their info they may hesitate for a moment, because they don't want to be considered the "moron" in that situation. I don't think it will make a big effect but it will help other people become more aware that most of these "hackers" are mostly just con artists, instead of letting everyone live with the constant anxiety of godlike hackers being able to wreak havoc at will.
- danso 5y agoYou really think that any average person, given a login cookie, is equally able to blindly infiltrate a company and successfully exfiltrate its core assets, as long as they can sweet talk a single IT person?
- shadowgovt 5y agoBut no employees in this story were conned into giving out their login info. Instead, hackers acquired enough stolen data to become a passable simulacrum of an employee in the text-based virtual space of Slack, convinced someone they were a coworker, and had that someone hand over the simulated employee's extended credentials. "Hackers can appear to be someone you think you know" is exactly the amount of paranoia the public should have. Faking an authentic-looking request is the most common form of hack, whether that fake is the right 1's and 0's to an API, "Hey Bob, got a small problem..." over Slack, or "I'm the CEO, and I will have you fired if you don't fix this right now" in voice over the phone.
- deleted 5y ago[deleted]