Hacker News new | ask | show | jobs
by ASalazarMX 490 days ago
That time is still today, as people are still the weakest link. A talented scammer can convince people to give them access to their WhatsApp account despite the E2EE, 2FA, and SMS verification codes.

In Mitnik's version, he RTFMs, learned the technical lingo, procedures, and even the names of telco employees.

1 comments

100%

The majority of corporate breaches are a combination of poor Least Privilege practices and phishing/smishing.

Even with well secured, alert personnel, you often see ISPs and Telcos socially engineered to gain access to an employee account.