![]() |
| Click here for more of Dark Reading's Black Hat articles. |
"You could see them talking about where they were going and where they were in Afghanistan and Iraq ... some were uploading pictures with geolocation information, and we were able to see them," says Thomas Ryan, the mastermind behind the social network experiment and co-founder and managing partner of cyber operations and threat intelligence for Provide Security, who will present the findings later this month at Black Hat USA in his "Getting In Bed With Robin Sage" talk.
Ryan says Robin's Facebook profile was able to view coordinates information on where the troops were located. "If she was a terrorist, you would know where different [troops'] locations were," Ryan says.
Robin Sage gained a total of about 300 friends on LinkedIn, counting those who came and went, he says. All three of the phony woman's social networking accounts remain active -- the LinkedIn profile currently has 148 connections, the Facebook profile has 110, and the Twitter account has 141 followers. Ryan officially ran the experiment for 28 days starting in late December and ending in January of this year.
Among Robin's social networking accomplishments: She scored connections with people in the Joint Chiefs of Staff, the CIO of the NSA, an intelligence director for the U.S. Marines, a chief of staff for the U.S. House of Representatives, and several Pentagon and DoD employees. The profiles also attracted defense contractors, such as Lockheed Martin, Northrop Grumman, and Booz Allen Hamilton.
Lockheed and other firms made job offers to Robin, some inviting her to dinner to discuss employment prospects. "I was surprised at how people in her same command friended her -- people actually in the same command and the same building," Ryan says.
Among the security experts who Ryan says initially accepted Robin's invitations were Lares Consulting's Nickerson, Jeremiah Grossman, CTO and co-founder at WhiteHat Security, and Marc Maiffret, who says he figured it out pretty quickly because Ryan used graphics in the profiles that he also uses for his paintball group. Ironically, the once-infamous social engineer Kevin Mitnick is listed as one of "her" connections on LinkedIn as well.
Grossman says he coincidentally was writing a Facebook bot when Robin's friend request showed up on his placeholder Facebook profile, which he doesn't actually use. The bot program then accepted Robin as a friend. "I look at Facebook and LinkedIn as public record," Grossman says. "What difference does it make if you vet them or not -- you shouldn't be disclosing" private information on these profiles, he says.
Meanwhile, the real woman in the Robin Sage LinkedIn, Facebook, and Twitter profile photos has agreed to show up at Black Hat USA later this month to introduce Ryan for his presentation. Ryan says he confirmed that using her photo for the social network accounts was legal, as long as none of her personally identifiable information was used, and it was not. The woman apparently posed for photo shoots for a pornographic site, according to Ryan. He found the woman's photo by searching "emo chick" via Google, a reference to the punk/indie style and music.
"I created a whole profile on that, so that nothing could link back to who she really was," he says. He set up a Blogger account under the name Robin Sage, named after the U.S. Army Special Forces training exercise. Robin Sage is the final phase of special forces training before becoming a Green Beret -- but even that apparently didn't tip off some military and intelligence community people who accepted LinkedIn invitations or Facebook friend requests from her.
He purposely left several clues that Robin was a fake, including choosing a woman who appeared to be Eastern European and a potential spy, he says. He built a prestigious resume for Robin: a degree from MIT, an internship at the National Security Agency, and her current position at the Naval Network Warfare Command. Her address was that of BlackWater, the infamous military contractor.
Whenever someone got suspicious and questioned any of Robin's credentials or information, Ryan says he would change it on the fly. He had the perfect comeback for hesitant LinkedIn members: "'Don't you remember we partied together at Black Hat?'" That was usually all it took for them to accept the invitation, he says.
Ryan's social networking experiment isn't the first of its kind, however. Researchers Nathan Hamiel and Shawn Moyers two years ago at Black Hat demonstrated how they successfully impersonated security icon Marcus Ranum on the social networking site LinkedIn, even fooling Ranum's sister into connecting to the phony Ranum profile.
Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
How to Prevent an Illicit Data Dump
There are no silver bullets when it comes to protecting company and customer data from loss or theft, but there are technological and procedural systems that will go a long way toward preventing a WikiLeaks-like data dump. Here are some tips and tricks to help protect your organization's most sensitive information.
Email and Data Loss
Email encryption, rights management, email gateways, and full-on data loss prevention systems can keep corporate data secure. Here's a look at the pros and cons of each, to help you determine what?s best for your business.
An Insider Threat Reality check
Heightened concern that users could inadvertently expose or leak -- or purposely steal -- an organization's sensitive data has spurred debate over the proper technology and training to protect the crown jewels. In this special retrospective of recent news coverage, Dark Reading takes a look at how organizations are handling the threat -- and what users are really up to.
Other reports from the Insider Threat Tech Center:
| Sponsored by: |
Protection from Insider Threats
Preventing data misuse by trusted users is the most difficult information protection challenge. Insiders already have full authorization to the data, making traditional IT secure methods in effective. Learn about a more powerful security approach and proven strategies to prevent insider misuse.
Strategies for Protecting Intellectual Property
A company's intellectual property (IP) represents a significant portion of assets and a critical component of competitive differentiation, but the potential value of any IP is directly linked to its limit of acceptable use. Learn how you can put your IP to work within collaborative environments without undue risk and maximize competitive advantages.
Protecting Against WikiLeaks Type Events and the Insider Threat
The sensitive information supplied to WikiLeaks and other social justice websites comes from trusted insiders. Get the answers to the open gaps left in the WikiLeaks story and learn how you can prevent insider threats that are just as detrimental in your organization.
Insider Threat: An Inside Look at a Fortune 100 Company's Prevention Program
The ways and means by which a privileged user can successfully steal proprietary data today is staggering. One venerable company that suffered a devastating incident decided to do something about it. Find out how it built one of the most productive insider threat prevention programs in the Fortune 100.
Protection of Intellectual Property and Trade Secrets across a Global Enterprise
As a designer and manufacturer of industrial technology, this Fortune 50 company knew that securing their intellectual property (IP) and trade secret data was essential. It created a program to identify risks to their IP and trade secrets and soon caught a privileged user attempting to compromise IP. Download this case study to see a real example of intellectual property protection at work.
MORE NEWSFEED >>>