The Man Who Hacks Your Employees
wsj.com
wsj.com
More than once I've explained that providing all my details in this fashion directly contradicts the security policy of the banks, but it takes some convincing to get the phone operators to give you a number you can confirm is legitimate and call them back. Its clearly not on the call center script and they dont understand why I am being so pedantic.
If they say, "hm, that's not what I have here," I can be at least somewhat certain that they already have that information, and are probably legitimate. If they blindly accept it, then I know they ain't on the level.
Many times you can avoid the SSN by asking and being willing to jump though a couple extra hoops.
On pain of having the IB (Bt Security) jump up and down on you with size 9 boots - think the auditors in the laundry files but worse.
I refused, told the woman flat out she called me, I didn't call her, therefore she was getting no information from me. I also told her I was happy with my Cox account and had no interest in whatever it was she was trying to sell. To her credit, she thanked me and ended the call amicably which is exactly what should have happened imo.
I understand the need for it from the company's perspective, but for me it was strange, uncommon, and I'm just too damned cynical. Even if I were interested I would have insisted on calling back through Cox's number before speaking with someone.
There was a time when it was relatively safe to speak with someone who calls you like that, but it's been years since I've felt comfortable doing so.
I'm not so sure about that, I think it existed for all my life, just wasn't very common until now.
I remember over 20 years ago getting a phishing call trying to get personal information about me.
On the banks, I've never had westpac attempt this (I think,) but they do still have this bizarre 6 letter character limit to my online banking password where they just ignore any letters after 6 characters so it seems like you are secure but in fact are not very secure at all.
That's an everyday occurrence in some offices.
Probably the biggest clue is that the IT guy is "jolly." The IT guy generally isn't jolly. You know some shit is up :)
IT is magic to most - magic in the fact that they don't know how the trick is done or what is required for it. "hey, can you give me the serial number on your computer so I can configure the flux capacitor" seems like a reasonable request because you don't know what a flux capacitor is or what is needed for it to run. All you know is you need your internet and email to do your job and IT does all the magic to make that happen.
I wonder how well it would work to call people up and say, "Hi, this is Paul from IT, we're having some trouble with our intranet security color swatch generator this morning. You should be seeing pink. Is that right?"
If they do, however, know the token, then you have another problem altogether.
The problem with the token would be if it was the sole level of protection (just like simply changing your ssh port is not enough).
The sad thing is that as we open up more and more ways to "do" things remotely (like move all your checking account funds from your account) the more danger involved. In many ways this makes the whole requirement that you authorize at a specific terminal in a secure space make much more sense.
They'd get an email claiming to be from the help desk and BAM owned. My sensors would pick it up and cut their access off and they'd have to come to my desk for restoration. I was unfailingly polite and respectful. Didn't make anyone feel dumb, no berating, just a calm explanation of exactly what happened and how to avoid it in the future. No student ever had it happen to them a second time.
One staff member fell for phishes at least 5 times, though. The president of the college had to talk to that individual eventually.
We used to have fun with William the "Windows Tech team agent" (from India) . He (They) would call us at least once a week. I think they might have had a successful attempt otherwise why would they keep calling.
> MR. HADNAGY: Airports are always stressful. These ladies are always getting yelled at. If we make someone happy before we can ask for a free upgrade, that could work.
So now the question is: how do you make the agent happy enough to give you an upgrade? Just be polite?
This is so true lol. Many people don't realize all the valuable info they put up on social media. Great article btw.