Social Hacking

From Wikipedia, the free encyclopedia
Jump to: navigation, search

Social hacking describes the act of attempting to manipulate outcomes of social behaviour through orchestrated actions. The general function of social hacking is to gain access to restricted information or to a physical space without proper permission. Most often, social hacking attacks are achieved by impersonating an individual or group who is directly or indirectly known to the victims or by representing an individual or group in a position of authority.[1] This is done through pre-meditated research and planning to gain victims’ confidence. Social hackers take great measures to present overtones of familiarity and trustworthiness to elicit confidential or personal information.[2] Social hacking is most commonly associated as a component of “social engineering”.

Although the practice involves exercising control over human behaviour rather than computers, the term "social hacking" is also used in reference to online behaviour and increasingly, social media activity. The technique can be used in multiple ways that affect public perception and conversely, increase public awareness of social hacking activity. However, while awareness helps reduce the volume of hacks being carried out, technology has allowed for attack tools to become more sophisticated.

Social Hacking Techniques[edit]

Carrying out a social hacking attack involves looking for weaknesses in user behaviour that can be exploited through seemingly legitimate means.[3] Three popular methods of attack include dumpster diving, role playing, and spear-phishing.

Dumpster Diving[edit]

Sifting through garbage is a popular tactic for social hackers to recover information about the habits, activities, and interactions of organizations and individuals. Information retrieved from discarded property allows social hackers to create effective profiles of their targets. Personal contact information such as employee titles and phone numbers can be appropriated from discarded phone books or directories and used to gain further technical information such as login data and security passwords. Another advantageous find for social hackers is discarded hardware, especially hard drives that have not properly been scrubbed clean and still contain private and accurate information about corporations or individuals.[4] Since surfing through people’s curbside garbage is not a criminal offence and does not require a warrant, it is a rich resource for social hackers, as well as a legally accessible one. Dumpster diving can yield fruitful, albeit smelly results for information seekers such as private investigators, stalkers, nosy neighbours, and the police.

Roleplaying[edit]

Establishing trust by fooling people into believing in the legitimacy of a false character is one of the main tenets of social hacking. Adopting a false personality or impersonating a known figure to trick victims into sharing personal details can be done in person or via phone conversation.

In person[edit]

By posing as third party maintenance workers in an office building, medical practitioners in a hospital, or one of many other forms, social hackers can get past security personnel and other employees undetected. In both examples, uniform apparel is associated with specific job functions, giving people reason to trust impersonators. A more complicated manoeuver would involve a longer planning cycle, such as taking up employment inside an organization that is being targeted for an attack.

In the movie Ocean’s Eleven, a sophisticated crew of con artists plot an elaborate heist to rob three popular Las Vegas casinos by assimilating themselves in the everyday activities of the casinos' operations. Although the heist is executed in less than a day, the planning cycle is long and notably fastidious. An imperative function of the attack is to present credibility in the roles being impersonated, to which attention to detail is inevitably required.

Tailgaiting[edit]

Tailgaiting is the act of following someone into a restricted space, such as an office building or an academic institution. Third party maintenance workers, or medical personnel, as mentioned above, often have limited cause to justify their credibility because of their appearances. Similar to role playing, tailgaiting functions around the assumption of familiarity and trust.[5] People are less likely to react suspiciously to anyone who appears to fit in to the surrounding environment, and will be even less liable to question individuals who don’t call attention to themselves. Following behind someone in an unassuming fashion may even eliminate the need to establish a rapport with authorized personnel.

Spear Phishing[edit]

Online social hacks include “spear phishing” in which hackers scam their victims into releasing sensitive information about themselves or their organization. Hackers will target individuals within specific organizations by sending emails that appear to come from trusted sources including senior officials within the organization who hold positions of authority. To appear convincing, a social hacker's email message has to establish a tone of familiarity that belies any suspicion from its recipient. The email is designed to put forth a request for information that ties logically to the person sending it.[6] Often, company employees will fall prey to these emails and share personal information such as phone numbers or passwords, thinking that the information transfer is taking place in a secure environment. In more sinister scenarios, the emails from hackers may be embedded with malware that infects victims’ computers without their knowledge and secretly transfers private data directly to hackers.[7]

A successful example of spear phishing was highly publicized in the news media in January 2014, when Target, a U.S.-based retailer, experienced a security breach that allowed hackers to steal customers’ credit card and personal data information.[8] Later, it was revealed that the cyber criminals were able to access Target’s financial and personal data files by targeting a third party mechanical company that had access to Target’s network credentials. The social implications of such a high profile social hack affect Target’s popularity as a retailer, but also consumers’ trust and loyalty towards the brand.

Security[edit]

Although Target may not have been slacking in its security, the hackers were able to infiltrate Target’s network indirectly, by identifying a third party company with by access to Target's credentials. The social hack was in defrauding employees of the third party to divulge sensitive informaton, while the cybercrime was conducted by means of a malware infected email phishing attack.[9] The need for vigilant online security is highlighted by cyber-attacks against corporations like Target as well as other global businesses and high-traffic websites. Even small websites are vulnerable to attacks, specifically because their security protection is presumed to be low.[10] In Target’s case, the third party mechanical company had inadequate security software which left them open to a malware attack.[11]

In a similar incident, Yahoo Mail also announced in January 2014 that their system had been hacked and a number of user email accounts had been accessed.[12] While the origin of the cause was unclear, poor security was again at the centre of the trouble. In both cases, large corporations with assumed understanding of security policies were compromised. Also in both cases, consumer data was stolen.[13]

In a study by Orgill et. al, an observation is made that “it is important that each person responsible for computer security ask if their system is vulnerable to attacks by social engineers, and if so, how can the effect of a social engineering attack be mitigated.” [14] Using strong passwords[15] is one simple and easy method that assists in such mitigation, as is using reliable and effective anti-virus software. Other preventative measures include using different logins for services used, frequently monitoring accounts and personal data, as well as being alert to the difference between a request for help and a phishing attempt from strangers.[16]

Ethical Hacking[edit]

To counter security breaches at the hands of social hackers as well as technical hackers, companies employ security professionals, known as ethical hackers, or more popularly, white hat hackers, to attempt to break into their systems in the same manner that social hackers would employ. Ethical hackers will leverage the same tools methods as hackers with criminal intent but with legitimate objectives. Ethical hackers evaluate security strengths and weaknesses and provide corrective options. Ethical hacking is also known as penetration testing, intrusion testing and red teaming.[17]

Impacting Social Media[edit]

The internet affords social hackers the ability to populate content spaces without detection of suspicious behaviour. Social hacking can also occur in environments where user-generated content is prevalent. This includes the opportunity to influence opinion polls and even to skew data beyond a point of validity. Social hacking can also be used to provide favourable reviews e.g. on product websites. It can also be used to counter negative feedback with an influx of positive responses e.g. on blog or news article comment sections. Social hacking can cause damage to the online profile of a person or a brand by the simple act of accessing information that is openly available through social media channels.[18]

Technology Appropriation[edit]

Technology appropriation can be perceived as a type of social hacking in that it involves social manipulation of a technology. It describes the effort of users to make sense of a technology within their own contexts beyond adopting its intended use. When this happens, the use of the technology can change. Adaptation of a technology can incorporate reinterpretation of its function and meaning, to the effect that the technology itself can take on a new role. Appropriation accentuates that the user adjusts the technology for his own best practice, while adaptation advises that the use sometimes changes in general.[19]

Social Enterprise[edit]

Social hacking is also affiliated with social enterprise. Social enterprise can be represented in the form of for-profit or non-profit organizations that encourage socially responsible business strategies for long-term environmental and human well-being. The concept of socially hacking new enterprises within the existing capitalist structure is a human endeavour that encourages people to re-evaluate the social systems that we are accustomed to, in order to identify the problems that are not being addressed.[20] New enterprises can then be created to replace the old with systems that reinforce sustainability and regenerative growth.

See also[edit]

References[edit]

  1. ^ http://www.cwu.edu/~tiddr/Courses/Archive/ACCT565/WebQuests/04SocialEngineering/04SocialEngineeringWebQuest.pdf
  2. ^ Hodson, Steve (August 13, 2008). "Never Mind Social Media, How About Social Hacking?". Mashable. 
  3. ^ http://www.computerweekly.com/tip/Social-hacking-The-easy-way-to-breach-network-security
  4. ^ http://www.cwu.edu/~tiddr/Courses/Archive/ACCT565/WebQuests/04SocialEngineering/04SocialEngineeringWebQuest.pdf
  5. ^ http://www.pcworld.com/article/182180/top_5_social_engineering_exploit_techniques.html
  6. ^ http://www.techradar.com/news/internet/phishing-just-got-personal-avoiding-the-social-media-trap-1224150
  7. ^ http://searchsecurity.techtarget.com/definition/spear-phishing
  8. ^ http://www.huffingtonpost.com/2014/02/12/target-hack_n_4775640.html
  9. ^ http://krebsonsecurity.com/2014/02/email-attack-on-vendor-set-up-breach-at-target/
  10. ^ http://thenextweb.com/dd/2014/04/02/stop-social-hackers-before-attack/
  11. ^ http://krebsonsecurity.com/2014/02/email-attack-on-vendor-set-up-breach-at-target/
  12. ^ http://www.forbes.com/sites/jameslyne/2014/01/31/yahoo-hacked-and-how-to-protect-your-passwords/
  13. ^ http://www.biztechmagazine.com/article/2014/01/snapchats-data-breach-should-be-wake-call-startups
  14. ^ http://dl.acm.org/citation.cfm?id=1029577/
  15. ^ http://gcn.com/Articles/2012/05/23/Military-dating-hack-government-social-media-risks.aspx?Page=2
  16. ^ http://lifehacker.com/5933296/how-can-i-protect-against-hackers-who-use-sneaky-social-engineering-techniques-to-get-into-my-accounts
  17. ^ http://dx.doi.org.myaccess.library.utoronto.ca/10.5120/229-380
  18. ^ http://www.usatoday.com/story/tech/columnist/2014/01/02/snapchat-breach-new-tech-economy-john-shinal-usa-today/4250487/
  19. ^ http://www.igi- global.com/dictionary/technology-appropriation/29492 http://www.creativeapplications.net/reviews/appropriating-interaction-technologies-social-hacking-at-itp/
  20. ^ http://www.theguardian.com/social-enterprise-network/gallery/2014/feb/21/from-afripads-to-zamalasha-social-enterprise-stories-from-africa-in-pictures/print