Having been at two of his talks, I can assure you that the man is no joke.
Sure, Social Engineering can look a bit voodoo-y but it's a tool that no one should underestimate, human error is the biggest and easiest to exploit breach one could hope for.
This is absolutely the case (source: I'm a former pentester in charge of the social engineering).
SE had two guarantees for every organization we were hired to pentest.
* We would get the information/access we wanted
* It would be easy
Chris is a pioneer in this branch of the industry and has done a great job of highlighting the importance of social engineering through his research, books, and the CTF at Defcon (which is awesome to watch if you get the chance).
Additionally to posing as an authority and creating some pressure, they also seem to add a general awkwardness to the conversation that may make the user want to get it over with.
Comments
Having been at two of his talks, I can assure you that the man is no joke.
Sure, Social Engineering can look a bit voodoo-y but it's a tool that no one should underestimate, human error is the biggest and easiest to exploit breach one could hope for.
This is absolutely the case (source: I'm a former pentester in charge of the social engineering).
SE had two guarantees for every organization we were hired to pentest.
* We would get the information/access we wanted
* It would be easy
Chris is a pioneer in this branch of the industry and has done a great job of highlighting the importance of social engineering through his research, books, and the CTF at Defcon (which is awesome to watch if you get the chance).
Like this one?
https://www.youtube.com/watch?v=DB6ywr9fngU#t=4m23s
Additionally to posing as an authority and creating some pressure, they also seem to add a general awkwardness to the conversation that may make the user want to get it over with.