Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

7/27/2016
01:00 PM
Terry Sweeney
Terry Sweeney
Slideshows
Connect Directly
Facebook
Twitter
RSS
E-Mail

7 Ways To Charm Users Out of Their Passwords

While the incentives have changed over time, it still takes remarkably little to get users to give up their passwords.
2 of 8

Milk Chocolate or Dark?

As any social engineer will affirm, you catch more flies with honey than with vinegar. The chocolate-for-passwords stunt has been replicated numerous times in the last 20 years; in a 2004 test, more than 70% revealed their computer password for a chocolate bar; more unsettling, 34% volunteered it with no bribe at all. Subsequent variants on the chocolate offer have turned up psychological insights around fair play and reciprocity. Research unveiled earlier this year by the University of Luxembourg showed that if chocolate was only given out afterwards, 30% of participants revealed their passwords, but if received beforehand, 44% shared their password.

Image Source: Wikimedia Commons

2 of 8
Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
<<   <   Page 2 / 2
JulietteRizkallah
100%
0%
JulietteRizkallah,
User Rank: Ninja
7/28/2016 | 11:43:51 AM
Re: Wow...
Well, i hope you use unique password because many times hackers will test the password they obtain - by theft, bribe or money - against many other systems until they get into the one they want access to.  You may think you can just chnage your password as soon as revealed and all is safe but hackers are not that stupid, they usually do not ask for the password of the system they wnat access to, they want to study your passwords, test them against other corporate systems until they get their way in.  And be worried, there is always one app you forget that will let them in!
T Sweeney
100%
0%
T Sweeney,
User Rank: Moderator
7/28/2016 | 10:21:40 AM
Re: Wow...
Ha! Thanks, Whoopty... that's a better title, actually: 7 Ways to Bribe Users! I'll admit I was surprised at how many ways there were to get users to give up the goods. Some little treat is actually a great conversational opener for a social engineer, provided they're willing to try it in person and forego the anonymity of the phone.

The other surprise: How many users will give up their passwords just by being asked... no incentive required. What's up with that?
Whoopty
100%
0%
Whoopty,
User Rank: Ninja
7/28/2016 | 8:02:00 AM
Wow...
I thought this piece would be about legitimate social engineering techniques, not outright bribery of people! I'm shocked so many would give up information for a pen.

A cookie I can understand but still...

I might be tempted by the cash, but only because I would immediately change my password after they gave it to me. 
<<   <   Page 2 / 2
Why Vulnerable Code Is Shipped Knowingly
Chris Eng, Chief Research Officer, Veracode,  11/30/2020
Inside North Korea's Rapid Evolution to Cyber Superpower
Kelly Sheridan, Staff Editor, Dark Reading,  12/1/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-27409
PUBLISHED: 2020-12-04
OpenSIS Community Edition before 7.5 is affected by a cross-site scripting (XSS) vulnerability in SideForStudent.php via the modname parameter.
CVE-2020-27408
PUBLISHED: 2020-12-04
OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.
CVE-2020-27765
PUBLISHED: 2020-12-04
A flaw was found in ImageMagick in MagickCore/segment.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. This would most likely lead to an impact to application availability, but could potentially cause ot...
CVE-2020-27766
PUBLISHED: 2020-12-04
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned long`. This would most likely lead to an impact to application availability, b...
CVE-2020-27767
PUBLISHED: 2020-12-04
A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of types `float` and `unsigned char`. This would most likely lead to an impact to application avai...