(no title)
KB
|
16 years ago
Having worked for a Defense Contractor and been forced to go through social engineering training in the past, the idea of gathering information like this is very real and happens everyday. Hopefully this makes people think twice before exposing certain personal information online for all to see.
ShabbyDoo|16 years ago
Was the class actually worthwhile, or was it just CYA? Some sort of taxonomy/formalisms for thinking about social engineering would be cool. I have no structured mental model now.
RK|16 years ago
KB|16 years ago
An easy example I remember being presented was a case where a foreign government may find out about a defense contractor conference and will send someone to nearby hotels to just sit around at the lounge bar and simply strike up conversations with those around. Needless to say, most people with a few drinks in them and a friendly person to talk to will be fairly candid with who they are, where they work, where they live, what they do, etc, etc, etc. All of this information would then be compiled into a folder on an individual and once enough data is collected it could potentially be used to blackmail or maybe even counterfeit someone's identity to steal government secrets.
To me, the main goal of the training was to demonstrate how easily another person or government could gather extensive personal information on an individual and potentially use it to gain access to government secrets. Teaches you to take extra care with the information you share publicly.
timwiseman|16 years ago