How to master the art of deception like a hacker
How to master the art of deception like a hacker
7:40

How to master the art of deception like a hacker

Privacy
Wow. [LAUGH] Thanks for finding out passwords. Snow. Stephanie, you are a social engineer And your title is Chief People Hacker. Yes. At IBM, that is the coolest job title ever. And for the past three weeks, you have been hacking, attacking, and social engineering My colleague Graham Cates and myself, you found so much information that it generated a 20 page report. That is amazing and horrifying. [LAUGH] But let's start with the basics. Okay. When we say social engineering What do you mean specifically? What does this type of hacking entail? So social engineering is convincing people to perform an action or give out information that's not normally something they would do. So it's really Going out there and seeing what information you can get from them. Specifically we look at phishing. So that's sending out an e-mail with malicious links or attachments. And what a lot of people don't realize is Is if they click on the link or open the attachment, it could give someone access to their information or even their computer. You found out a lot about den Yes. But you found out just a crazy amount about me and my whole family really my wife, my my young daughter when she was born, my address my cell phone number It's kind of a whole different world of information about me and I'm curious what that could give you access to. So, with your cell phone number and seeing different accounts you have, I know that your interested in food and you like to take pictures of food. So as an attacker I could use that information and send you a text message, but it could contain a malicious Clink. Or if I know that you're out of the town and I did see a post where the family was going on vacation,that's something that as an attacker I would know that your house is most likely vacant.>> What's fascinating Stephanie is that your skills are so good That you're in disguise right now. I am yes. [LAUGH] Let's take a look at Stephanie Snow post disguise. Absolutely so I am in disguise now this is not what my hair looks like at all [LAUGH]. So I use this [UNKNOWN] a lot when I go on site cuz I don't want be recognized or am I have to use multiple personalities? If something does work the first time, I have to try something else. And this really helps me [UNKNOWN] pretending to be someone specific, like a flower delivery person I'm gonna change into two uniforms. The wig that I use is just something I would use for an auditor and I'd wear a suit. I actually go online and try to find information and pictures of people in those same job roles to look as much like them as I can. So you've now taking up your disguised you're dressed as yourself presumably. So you didn't actually break into the CBS news headquarters. But you brought along tools that could show us how you would be able to do that if you wanted. Absolutely, so I actually made you a fake card, and can I see that? Yeah. So to show how this would work, this is like a regular RFID system that many buildings have. So you need to barge in to get access to the building. So your card is programmed and it works. What I would then do is take my RFID captioned device. And what this is, is this is a longe-range reader. I hide it in my purse, and nobody knows it's there. So what I do is, I wear my purse around. And I would stand next to an elevator, in line at the coffee shop, and all I would need is 20 inches of distance between my purse and your badge. And I would be able to capture all of the data that is on your badge. So then I would go back to my hotel room And I'll get the data off of this reader. [BLANK_AUDIO] So I have a micro SD card in here that I would then pull out, plug into my computer, and I would use this Proxmark. What this does it will [UNKNOWN] the data that I give it onto a new card. So I'm taking the data that I captured from your card, and I am programming it to this new card. So it will now work just as if it was your card. I didn't do anything wrong, but you were able to get access to the building, using me as a vulnerability. Exactly. And that's just very, very close distance. I don't even have to be at your building. I could be in line for lunch or somewhere just close to employees. All right, Stephanie, a large part of your job requires that you build trust, build a rapport, and you do that often by spoofing a phone number to appear as though it's coming from a trusted source. It could be a friend, it could be a family member, it could be a bank, right? And all of us have seen these spam robo calls on our phone. Sometimes a robo call that get me look as though they're coming from my number or a very similar number. You can even spoof how two different contacts could look like each other. Tell me how this process works, and can you show us?>> Yes, absolutely. So you need a mobile app, and I'm not gonna tell you which one.>> So you are going to make it look as though my phone is being called from Graham's phone.>> Right. All right. [BLANK_AUDIO] I feeling a calling and It says Graham Kates. But it is in fact, you calling you from your mobile phone. Exactly. I think there's something that's really important to point out here, which is that it's not that you designed some sort of program but it's that anyone could get that and do the same thing. Absolutely in it's just It's an app and you can make your phone number appear as anyone. Snow you've demonstrated to us that we're absolutely unsafe everywhere. How do we protect ourselves? That's a great question. So how you can protect yourself online is really stop and think about what you're posting. Do you really need to tell everyone that you're going on vacation? And also check websites to see if your information is leaking anywhere so you can get that removed. Those two things are very important when it comes to social media. As far as your badges, there's no reason you need to take it everywhere with you or leave it in your car. It should be hidden so that someone like me or an attacker can't visually see it to recreate a copy or clone it. Before you came here you told us you had some surprises to show us, some things that you found about us that you didn't necessarily want to put in your report, and we're ready to see them. All right. Graham, this is for you. Dan, for you. Man. The magical mystery envelope. Wow. [LAUGH] Thanks for finding our password [UNKNOWN] This is [LAUGH] Maybe my oldest password, it's what I have being trying to phase out Okay From my various web sites [LAUGH] When I was just like a little kid and I didn't know any better. So unfortunately things like this are in data breaches and if I can get it, so can attackers. [BLANK_AUDIO]

Up Next

What AirPods Rumors Tell Us About Apple's Health Ambitions
240424-omt-next-airpods-v07

Up Next

What AirPods Rumors Tell Us About Apple's Health Ambitions

What is the Fediverse?
240418-fediverse-winged

What is the Fediverse?

The Missing Piece to Apple's Eco-Friendly Mission
240418-site-omt-the-core-problem-of-apples-green-goals-v1.jpg

The Missing Piece to Apple's Eco-Friendly Mission

Boston Dynamics Retires Its HD Atlas Robot
p1022506-00-00-01-20-still001

Boston Dynamics Retires Its HD Atlas Robot

Apple and Disney's Unique Bond: Why Vision Pro Needs the Mouse
240411-site-can-disney-save-the-apple-vision-pro-v1

Apple and Disney's Unique Bond: Why Vision Pro Needs the Mouse

The Ocean Cleanup's System 03 Collects Plastic Pollution at Record Levels
The Ocean Cleanup System 03

The Ocean Cleanup's System 03 Collects Plastic Pollution at Record Levels

Latest iOS 18 Rumor Roundup: New Designs, AI Tricks
240404-yt-omt-ios-18-siri-ai-v06

Latest iOS 18 Rumor Roundup: New Designs, AI Tricks

Apple to Talk AI in June: This WWDC Is a Big Deal
240328-yt-omt-wwdc24-v07

Apple to Talk AI in June: This WWDC Is a Big Deal

What Google Gemini AI on the iPhone Could Look Like
240321-site-apple-and-gemini-ai

What Google Gemini AI on the iPhone Could Look Like

Microsoft Surface Pro 10, Surface Laptop 6 Are Here
240320-site-microsoft-surface-pros-first-look-v2

Microsoft Surface Pro 10, Surface Laptop 6 Are Here

Tech Shows

The Apple Core
apple-core-w

The Apple Core

Alphabet City
alphabet-city-w

Alphabet City

CNET Top 5
cnet-top-5-w

CNET Top 5

The Daily Charge
dc-site-1color-logo.png

The Daily Charge

What the Future
what-the-future-w

What the Future

Tech Today
tech-today-w

Tech Today

Latest News All latest news

Meta Expands Its Mixed Reality Beyond the Quest Headsets Explainer
Meta Quest 2

Meta Expands Its Mixed Reality Beyond the Quest Headsets Explainer

What AirPods Rumors Tell Us About Apple's Health Ambitions
240424-omt-next-airpods-v07

What AirPods Rumors Tell Us About Apple's Health Ambitions

Robosen's Megatron Transformer Is Too Much Fun for an Evil Robot
240419-megatron-v04

Robosen's Megatron Transformer Is Too Much Fun for an Evil Robot

Apple May Give FineWoven Accessories One More Season
finewoven-240424-land-00-00-13-04-still003

Apple May Give FineWoven Accessories One More Season

US vs. TikTok: What Happens Next
240424-yt-tiktok-vs-us-v04

US vs. TikTok: What Happens Next

Battle of the Humanoid Robots: MenteeBot Is Ready
240423-yt-menteebot-ai-robot-v08

Battle of the Humanoid Robots: MenteeBot Is Ready

Most Popular All most popular

First Look at TSA's Self-Screening Tech (in VR!)
innovation

First Look at TSA's Self-Screening Tech (in VR!)

Samsung Galaxy S24 Ultra Review: More AI at a Higher Cost
240123-site-samsung-galaxy-s24-ultra-review-4

Samsung Galaxy S24 Ultra Review: More AI at a Higher Cost

'Circle to Search' Lets Users Google From Any Screen
circlesearchpic

'Circle to Search' Lets Users Google From Any Screen

Asus Put Two 14-inch OLEDs in a Laptop, Unleashes First OLED ROG Gaming Laptop
asus-preces-00-00-25-11-still003

Asus Put Two 14-inch OLEDs in a Laptop, Unleashes First OLED ROG Gaming Laptop

Samsung Galaxy Ring: First Impressions
samsung-galaxy-ring-clean

Samsung Galaxy Ring: First Impressions

Best of Show: The Coolest Gadgets of CES 2024
240111-site-best-of-ces-2024-1

Best of Show: The Coolest Gadgets of CES 2024

Latest Products All latest products

Robosen's Megatron Transformer Is Too Much Fun for an Evil Robot
240419-megatron-v04

Robosen's Megatron Transformer Is Too Much Fun for an Evil Robot

Battle of the Humanoid Robots: MenteeBot Is Ready
240423-yt-menteebot-ai-robot-v08

Battle of the Humanoid Robots: MenteeBot Is Ready

2025 Audi Q6, SQ6 E-Tron: Audi's Newest EV Is Its Most Compelling
cnet-audiq6

2025 Audi Q6, SQ6 E-Tron: Audi's Newest EV Is Its Most Compelling

Hands-On with Ford's Free Tesla Charging Adapter
pic3

Hands-On with Ford's Free Tesla Charging Adapter

Nuro R3 is an Adorable Self-Driving Snack Bar
240320-site-nuro-r3-first-look-v1

Nuro R3 is an Adorable Self-Driving Snack Bar

First Look: The $349 Nothing Phone 2A Aims to Brighten Your Day
240304-site-nothing-phone-2-first-look-v3

First Look: The $349 Nothing Phone 2A Aims to Brighten Your Day

Latest How To All how to videos

Tips and Tricks for the AirPods Pro 2
airpods-pro-2

Tips and Tricks for the AirPods Pro 2

How to Watch the Solar Eclipse Safely From Your Phone
screenshot-2024-04-03-at-15-47-11.png

How to Watch the Solar Eclipse Safely From Your Phone

Windows 11 Tips and Hidden Features
240311-site-windows-11-hidden-tips-and-tricks-v2

Windows 11 Tips and Hidden Features

Vision Pro App Walkthrough -- VisionOS 1.0.3
VisionOS 1.0.3

Vision Pro App Walkthrough -- VisionOS 1.0.3

Tips and Tricks for the Galaxy S24 Ultra
240216-site-galaxy-s24-ultra-tips-and-hidden-features-2

Tips and Tricks for the Galaxy S24 Ultra

TikTok Is Now on the Apple Vision Pro
tiktok-on-vision-pro-clean

TikTok Is Now on the Apple Vision Pro