Red team hacker on how she breaks into buildings and pretends to be the bad guy
theregister.com
theregister.com
Same thing with attitudes to security of leadership teams. And if past events are indicative, there's way more leadership teams that don't give a rats ass about security than ones that do. Particularly when you're holding other people's valuables (data).
I've now coined the phrase, accidentally.
Along those lines, however, it's peace of mind against an actual intrusion, but it's also peace of mind against lawsuits for dereliction of duty, etc.
If you are the kind of company that has a focus on all aspects of security, and assumes a sophisticated actor is attacking, you will have a better chance at defending against unsophisticated actors.
If you plan your security around only defending 'less-sophisticated' actors then you might quickly find one slips through the cracks.
I think the sad part is that they had probably had some security guy tell them this already but people where just making fun of him because people don't believe things they can not see - so it takes a "pretend to be SPYs charade" to make people actually care.
So sadly for many only the threat of dismissal forces those unhappy ranks to do their job. Others have a strong work/duty ethic, and will do their best. One thing that can help overall is an entire corporate culture, where everyone is lambasted for such failures.
"You saw that <security guard> wasn't doing his job, and you didn't tell anyone? You're in trouble too!", and so on.
That is precisely what you not want to do, all that breeds is a culture of hyper-paranoid ass-covering and blame deflection.
So. Much. This.
The number of people who do “just enough” to not get fired is staggering.
There is no “work ethic”.
At least in the military when somebody fucks up during training the entire $GROUP gets punished. It doesn’t take long before people start taking “rules” seriously.
There needs to more consequences and accountability.
It’s a threat of violent coercion, even though daddy never personally hit you or anyone you served with.
It’s how all abusive relationships work, they just operationalized and scaled it to an unprecedented degree.
And then you come out of that abusive relationship with a quick reintegration course and track your duty, but no honor, back to the private sector. If vets weren’t a protected category, they’d be subject to more discrimination due to the warped psyche basic training is designed to produce.
only the threat of dismissal forces those unhappy ranks to do their job
or, you know, just pay them properlyHere's an example. Your salary is $1M per year, or $10k. In both cases, you hate work, hate your job, don't want to do it, and...
can never be fired.
How does better pay help?
Better pay may help, but only conjoined with the threat of it being taken away if you don't do your job.
And amusingly, you throw out the "better pay" line without even knowing the salary.
That's probably higher than average.
But the lowly security guard also does not want to piss of a higher class being, which is so high, it is above all that. "How dare you question me! Don't you know who I am?"
This attitude for example is what makes it hard for that low guard.
Generally, if you act, like you belong somewhere and have the right to do so, your are seldom stopped.
The counter defence would be indeed, just follow strictly security protocoll for everyone with no exceptions.
And well, hire professional security. I briefly worked in security, in a company supposedly with higher standard. Well, I would not hire them, for anything serious. General staff morale is very low, in that low payed sector.
So pay a reasonable wage that actually boosts the morale of the security staff to ensure they do their best and not just act like a velvet rope?
Maybe, but you better believe everyone has to scan a valid badge if they want to get into the office in the first place. And through every door.
Companies that want to prevent tailgating need to spend the money on mantraps or other infrastructure that is clearly designed to allow one person through at a time.
I worked at a place that stressed this at company meetings - “no holding doors, if someone says they forgot their badge don’t let them in etc”
At one meeting the CEO got up and talked and praised one of the employees because they actually did this to him, the CEO; shut the door in his face made him walk back to his car to get his badge. Was very funny to see a place actually walk the talk on this.
Overall though of course you’re right. People are going to be nice and you can’t stop it.
Any system that relies on humans always remembering everything and acting perfectly is inherently naive and broken. The security guard isn't there to check badges in a properly secure environment, only to respond to incidents.
In fact this is the episode referring to Alethe from the article:
It’s mostly story telling but it’s entertaining and thought provoking too
This has nothing to do with DEI hiring. I mean: why is it up to women or people of different ethnicity to spot people who should not be in a building?
Why can't men dump this perceived bias and not be so - allegedly - vulnerable?
To me this really reads as an excuse to be dismissive of the accomplishment of a women who was succesvol at her job.
The certainly can, but the average minimum-wage front desk security guard tends to not. Doing so takes training. There are security guards specifically tipped to counter this sort of thing. It is taught in areas such as national security and, ironically, the entertainment industry.
And why would this diminish one's accomplishments? For a physical pen tester, getting through is all that matters. Putting the effort in to being more physically attractive, as a tool, should not be diminished. Have a look at some of the spies that Russia has sent to penetrate US systems. Nobody thinks any less of them for being attractive. It is a very powerful weapon that certainly takes more effort than learning to metasploit.
It's the combination of being attractive (but not overtly so), looking professional, looking as if you know exactly what you are doing, and being able to shrug off any questions in a plausible manner. You have to be likeable and trustworthy, and being attractive, apparently, helps to achieve that.
Besides, a red team could just as easily send in the buff handsome black vending machine repairman if they figured that would get them past the security detail staffing the front entrance that day more easily, or team up and send in both; whoever gets the most questions asked just falls into the stalling routine whilst the other is waived through.
It all comes down to training and giving a fuck about the job (i.e., being paid decently and made to feel appreciated).
How about not relying solely on error prone humans to grant access to places. locks have been a thing for a milenia or do you also use a diverse team of log in guards to decide who can use what systems.
Except that a friendly smile and bit of eye contact can often prove enough to slip in behind after someone else opens a door. I know of buildings with claustrophobically small turnstile doors specifically to address this problem.
One of their products is called "Cosmos" https://bishopfox.com/cosmos
Too many secrets?
What is that supposed to mean? Sneakers reference?
I feel like this is a repeating pattern for security companies these days. Trying to sell a holistic solution with fancy dashboards but essentially they're doing the same any script kiddie can do.
It's the active red team that impresses me more than these products like cosmos. And they surely don't have the resources to offer active pen testing to all their clients.
yes
https://www.darkreading.com/cybersecurity-analytics/security...
But at that point, the victim already feels like they screwed up by missing an email last week, and now they feel indebted to the attacker. "They feel like they owe me. Then I can say, 'while we are on the phone right now, is it OK if I resend it to you? Can you go ahead and just do this one thing?"
I'm immune to this one. Don't send me a fucking email if it's something important. Email can wait. Email can always wait. Email is a filing system for details that are only ever useful when someone says "did you get that email?"
I don't feel indebted, I feel annoyed that you expect me to have read your email and have it memorised for whenever it is you may show up to test me on the hyper-contextual trivialities it contained.
Always say you didn't get the email when someone asks, and do it with an unrepentant attitude; put them on the back foot. If you've got the time and mental space to recall random emails from x minutes, hours, days in the past, then you probably need to re-evaluate how you prioritise your time and tasks.
(This has been true for me for at least a decade. People still get horrified at my number of unread emails. I pity them and the time they spend curating their inbox - I'd rather get shit done or use my free time on literally anything else)
If you send me a physical letter and require that I'm home to receive it, not lose it in my piles of unopened mail, and reply eventually (with a physical mail? lol) it's already a lost cause.
Most likely I won't be able to take any note during a phone call, if by the most unbelievable chance I am able to pick up when you decide to call impromptu.
Text message, seriously? It's just for spam at this point. It's just the worst 'technical' solution. Unsecure, not travel-proof, etc...
An email leaves precise traces (when, who) can be archived, searched, muted or prioritized as I see fit. You can put text picture & urls inside & whatever else, that I can lookup on my own time.
If it's at all important : Send an email, then send follow-ups when it looks like the matter's urgency needs it (because as you said, obviously you can't assume I'll read it immediately and then remember it).
If it's important -to you- the onus is on you to pick the best technical way to deliver information, and then insist until you get your answer.
Wow. They must have some amazing commercial tenancy agreement in place to allow them to send unknown-to-the-tenant people into the premises to literally compromise the tenants network.
To me, that sounds like extraordinary grounds for legal action by the tenant.
is this trope still true? do companies still have open and unprotected smb drives as soon as you plug any device into network?
Her therapist must have a fun time.
F%#& Undercover Boss! Give me Undercover Boss gets hacked!
He would literally just walk into facilities and ask people to give them their passwords and they would give them.
The people working would also help him open wiring cabinets so he could do whatever he wanted.
I called a vendor once, wanting a server setting tweaked. I asked for the present state and when it came back completely different to what I was expecting I backtracked.
I’d queued changed on a competitors live environment. I don’t think you need an elaborate charade, just blaze in with confidence.
https://www.youtube.com/playlist?list=PLc7mVBABUGE5IITXKHvnX...