How I Socially Engineer Myself into High Security Facilities
motherboard.vice.com
motherboard.vice.com
It reads more like fiction.
Gross. The author explicitly brags about being "a terrible human being."
Aside from the sociopathy and embellishment, I get unease about the legality of the means used, considering the agent was contracted.
I could've audited the security controls and arrived at the same deficiencies without abusing people.
Nobody is going to pay attention to a 10 page report. They are instead going to pay attention to the fact that the person successfully got into the building.
If so, then that's mismanagement. Poor managers suddenly "paying attention" are unlikely capable of implementing proper controls.
Also, you're assuming these poor managers can contract well.
You can call it mismanagement, but humans aren't perfect. Humans are emotional being who, in many cases (but not all) will not take a threat seriously unless someone goes and does it.
It is not even necessarily mismanagement either. It could just be ignorance. IE, someone can talk all they want about hypothetical vulnerabilities, but if you aren't a security expert, you have no idea how realistic those threats are, no matter what the pen tester tells you.
Who knows, maybe the pen tester really is being paranoid.
It is much easier to actually convince someone that something is a problem by actually exploiting it. That's just an obvious fact.
And it seems like the pen tester in question agrees with me. Because she didn't right a report. She instead broke into the system, and what do you know it worked in their goal of convincing the company that their was a problem.
If you will noticez the company in question really did think that everything was secure. The pen tester really did need to do something extrodinary in order to convince them. So she did, and it worked.