<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Angels of security &#187; issa</title>
	<atom:link href="http://angelsofsecurity.com/blog/tag/issa/feed/" rel="self" type="application/rss+xml" />
	<link>http://angelsofsecurity.com/blog</link>
	<description>Musings of an infosec renegade</description>
	<lastBuildDate>Tue, 02 Aug 2011 19:01:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Secure wireless</title>
		<link>http://angelsofsecurity.com/blog/2009/12/03/secure-wireless/</link>
		<comments>http://angelsofsecurity.com/blog/2009/12/03/secure-wireless/#comments</comments>
		<pubDate>Thu, 03 Dec 2009 18:52:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Access Control Systems & Methodology]]></category>
		<category><![CDATA[issa]]></category>
		<category><![CDATA[physical security]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2009/12/03/secure-wireless/</guid>
		<description><![CDATA[Secure wireless Originally uploaded by bachrach44 I noticed this on the wall at a recent ISSA meeting. In addition to the obvious security issue I&#8217;m trying to bring attention to, there is a bonus security issue being illustrated here &#8211; you can see my reflection!]]></description>
			<content:encoded><![CDATA[<div style="float: right; margin-left: 10px; margin-bottom: 10px;"><a title="photo sharing" href="http://www.flickr.com/photos/bachrach44/4139122514/"><img style="border: solid 2px #000000;" src="http://farm3.static.flickr.com/2744/4139122514_e980a1851c_m.jpg" alt="" /></a></p>
<p><span style="font-size: 0.9em; margin-top: 0px;"><br />
<a href="http://www.flickr.com/photos/bachrach44/4139122514/">Secure wireless</a></p>
<p>Originally uploaded by <a href="http://www.flickr.com/people/bachrach44/">bachrach44</a><br />
</span></div>
<p>I noticed this on the wall at a recent ISSA meeting. In addition to the obvious security issue I&#8217;m trying to bring attention to, there is a bonus security issue being illustrated here &#8211; you can see my reflection!</p>
]]></content:encoded>
			<wfw:commentRss>http://angelsofsecurity.com/blog/2009/12/03/secure-wireless/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social Engineering is not for engineers</title>
		<link>http://angelsofsecurity.com/blog/2008/04/02/social-engineering-is-not-for-engineers/</link>
		<comments>http://angelsofsecurity.com/blog/2008/04/02/social-engineering-is-not-for-engineers/#comments</comments>
		<pubDate>Thu, 03 Apr 2008 02:45:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[social engineering]]></category>
		<category><![CDATA[issa]]></category>
		<category><![CDATA[psychology]]></category>

		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2008/04/02/social-engineering-is-not-for-engineers/</guid>
		<description><![CDATA[I&#8217;m a little behind on my reading, so I only just got to the January issue of the ISSA journal. In it was one of the best articles I&#8217;ve read on social engineering. The problem with most articles (or at least the ones I read), is that they approach social engineering from a technical perspective. [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m a little behind on my reading, so I only just got to the January issue of the <a href="http://www.issa.org/Members/Journal.html">ISSA journal</a>. In it was one of the <a href="http://www.issa.org/Library/Journals/2008/January/Timko-The%20Social%20Engineering%20Threat.pdf">best articles I&#8217;ve read </a>on <a href="http://en.wikipedia.org/wiki/Social_engineering_(computer_security)">social engineering</a>. The problem with most articles (or at least the ones I read), is that they approach social engineering from a technical perspective. However, far from what the name implies, social engineering is not in any way related to any of the engineering disciplines. SE is nothing more than a fancy name for a scam that happens to involve a computer. Rather than treat the SE threat as a technological threat, we should be treating it the same way we treat all scams &#8211; as a purely human threat and not a technological one. We should be turning to psychologists for help in tackling the problem, not networking experts.</p>
<p>In this article Dan Timko reports on research done by <a href="http://en.wikipedia.org/wiki/Robert_Cialdini">Robert Cialdini</a> on the psychology of influence. Cialdini enumerates 6 basic methods people use to influence others. They are:</p>
<ul>
<li>Reciprocation</li>
<li>Commitment and Consistency</li>
<li>Social Proof</li>
<li>Authority</li>
<li>Liking</li>
<li>Scarcity</li>
</ul>
<p>I&#8217;m not going to go in depth into each of these, but if you&#8217;re interested, here is <a href="http://www.fripp.com/art.of_influence.html">a good summary</a> of each. Suffice it to say that these methods are by no means limited to marketers &#8211; scam artists (sorry,&#8221;social engineers&#8221;) use all 6 without even necessarily knowing it.</p>
<p>The solution to scam of all sorts, just like the threat, should be based on social science and human behavior, not technical countermeasures (although they do certainly have their place). While Dan recognizes and says this, he does not stick true to those principles, concluding only that the best defense against social engineering is a strong security policy, user education, and the rest of the things ISSA members have been preaching for ages. If you ask me the solution (if there really is one) to social engineering will not come from someone with a CISSP, CISM, or CISA, but from someone with a PhD in psychology. The quicker we realize that, the quicker we can come to a real solution.</p>
]]></content:encoded>
			<wfw:commentRss>http://angelsofsecurity.com/blog/2008/04/02/social-engineering-is-not-for-engineers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

