ATHENS, 30 November 2004 — It’s interesting watching dozens of law-abiding network security professionals stand in line to shake hands and have a photo taken with a convicted criminal. They reminded me of the groupies who throw themselves at rock stars. Such behavior I’d only witnessed before at a few Microsoft events when some IT geeks would do almost anything to have a photo taken with Bill Gates.
Kevin Mitnick, the individual who was the focus of their adoration, is arguably the most famous hacker in the world. At one point he was held in prison in solitary confinement for eight months because a judge thought he might be able to initiate a nuclear strike from a prison payphone.
Released from prison in January 2002, Mitnick was banned from using the Internet until midnight on Jan. 21, 2003. Now reformed, Mitnick is working as an IT security consultant and heads his own firm “Defensive Thinking.” He has also authored two books. “The Art of Deception: Controlling the Human Element of Security,” was published in October 2002. “The Art of Intrusion: The Real Stories Behind the Exploits of Hackers, Intruders, and Deceivers,” is scheduled to be published in Spring 2005.
In his new book, Mitnick offers stories of real-life computer break-ins and shows how the victims could have prevented them. Mitnick’s reputation within the hacker community gave him credibility with the perpetrators of these crimes, who freely shared their stories with him and whose exploits Mitnick reveals in detail. They include:
• A group of friends who won nearly a million dollars in Las Vegas by reverse-engineering slot machines;
• Two teenagers who were persuaded by terrorists to hack into the Lockheed Martin computer systems;
• Two convicts who joined forces to become hackers inside a Texas prison;
• A “Robin Hood” hacker who penetrated the computer systems of many prominent companies and then told them how he gained access.
Most of Mitnick’s hacking relied on social engineering and that is the topic he spoke on at the Information Security Matrix Forum. According to Mitnick, “social engineering is a form of hacking that relies upon influence, deception and/or psychological manipulation to persuade unwitting people to comply with a request.”
Mitnick cited one survey that found social engineering to be responsible for 11 percent of all network attacks. Experts believe that in reality the percentage is even higher because it is often impossible to detect a social engineering attack. People just don’t want to admit that they’ve been tricked into giving out information that was quite possibly essential for the success of a crime.
Social engineering is being used in more and more attacks and everyone is vulnerable. Mitnick admitted that even he had recently been a target of social engineering. For more than an hour he spoke on the subject, interspersing his advice with examples of actual attacks.
Can breaches of data security due to social engineering be prevented? Hundred percent prevention is probably impossible due to human nature. However, Mitnick advised that 70 percent of all attacks could be stopped by having company staff call back to verify identity, rather than just immediately giving information out to a caller. Staff should understand what information is sensitive and what actions are restricted. Employees should be unafraid to say, “No,” if a requested action goes against company policy. Procedures should be developed to verify identity and authorization.
“Social engineering is the single most effective and dangerous threat to information security,” Mitnick asserted. “Effective security policies, procedures and processes are the only ways to try to defeat it. Educate your people. Raise awareness. And perhaps most importantly, evaluate adherence to security policies and procedures in each staff member’s annual performance review.”

