3 ms·
Maybe auditing. When I was a wee lad on American Online in the 90s, our biggest desire was to steal the most 31337 screen names. One way of doing this was learn
by notadev 5y ago
Maybe auditing. When I was a wee lad on American Online in the 90s, our biggest desire was to steal the most 31337 screen names. One way of doing this was learning of people who worked at the call centers you’d call for account problems. Once you were friendly enough, you could sometimes convince them to pull an account’s information for you. Then you’d call the call center from a pay phone and, using the stolen information, reset the password. This allowed you to get on the account for a while to brag. In some cases, you could permanently steal the AOL Instant Messenger (AIM) version of the screen name unbeknownst to the original account owner.
Anyway, AOL recognized this insider threat and audited and reviewed any access to their internal account systems (called CRIS or Merlin IIRC), which pretty much killed the method of using insiders since they were caught and fired pretty quickly.