« Back to blog

Fake femme fatale shows social network risks

Hundreds of people in the information security, military and intelligence fields recently found themselves with egg on their faces after sharing personal information with a fictitious Navy cyberthreat analyst named "Robin Sage," whose profile on prominent social networking sites was created by a security researcher to illustrate the risks of social networking.

In a conversation with Computerworld, Thomas Ryan, co-founder of Provide Security, said he used a few photos to portray the fictional Sage on Facebook, LinkedIn and Twitter as an attractive, somewhat flirty cybergeek, with degrees from MIT and a prestigious prep school in New Hampshire. Then he established connections with some 300 men and women from the U.S. military, intelligence agencies, information security companies and government contractors.

The goal, said Ryan, was to determine how effective social networking sites can be in conducting covert intelligence-gathering activities.

Here we see how "Social Networks" facilitate the hacker practice of Social Engineering: manipulating people into giving you access to systems or confidential information that could assist in the penetration of a system.
Whats particularly wild is how blatant "her" LinkedIn profile is. (seen here on boing boing http://www.boingboing.net/2010/07/23/faux-femme-fatale-fi.html)