The Art of Deception
I’m tidying up my books today. I had this huge pile of books by the bed and they ended up in a box while we were away. So, now I’m sorting through the box.
Kevin Mitnick’s book The Art of Deception is all about Social Engineering — human ways of beating security systems and getting access to things you aren’t supposed to. The book is intriguing as it decribes a series of cons, a series of techniques for getting access and information that you aren’t supposed to get by convincing people to give it to you, or setting up the circumstances around the call or request so people just trust you.
The idea is not to use these techniques to go and con people, but to get an awareness of what is possible and how easy it can be to break security when there is somebody you can call up and convince them to give you the password or something
People implementing any sort of IT systems need to read this. Typically we build IT security without considering the human element much. And people who are interested in cons and tricks will enjoy the descriptions of the techniques involved and the stories.
I wish the people at Clipsal would read this.. but more importantly I wish they read some books about IT first :)
Duncan,
My copy is up for grabs, Duncan. Shall I post it to the office for you?
Ashleigh has already bagged it. I’ll sent it to him.