Manipulating the Human Memory for Fun and Profit, or: Why you’ve never met Bugs Bunny in DisneyLand Hacking is not limited to technical things — like using a coffee machine to cook a soup — but also makes use of social engineering. Social engineering is the (mis)use of human behaviour like fixed action patterns, reciprocity or commitment and consistency. Simple social engineering attacks like phishing mails do not require much preparation, but more complex ones do so. Especially when one wants to set up some kind of advanced persistent threat in the psychological domain. So, besides the psychological fundamentals of social engineering we also did research on human memory, how it works, how it pretty much fails to store what really happened, and how it can be misused for a sinister purpose. The fundamental
The DeepSec 2013 keynote presentation featured the cultural background of China in order to better understand the news about impending „cyber doom“. The past year has shown that you need a lot more than hands-on information security if you want to make sense of incidents. Next to history and culture there is psychology. In his talk at DeepSec 2013 Stefan Schumacher make a good case for combining psychology and the scientific approach with topics of information security. Watch his talk online!
Have you ever considered the impact of the human mind on information security? Since our brain also deals with information,it should be an integral part of defence. Let’s take a look at psychology: At DeepSec 2013 Stefan Schumacher will give you an introduction into the psychology of security and why we need to improve scientific research in this particular field. Most research about security is done in Computer Science, Electrical Engineering and Mathematics and is about technology, algorithms and computability. However, all security issues can be traced back to human behaviour. Be it Social Engineering, the choice of weak passwords, users leaving the password on a note-it attached to the TFT, admins using MD5 as a password hash or developers ignoring testing regulations. Humans are making decisions, not computers. Therefore, security is defined by