|
|
|
|
|
by paxys
5 days ago
|
|
People are (rightfully) concerned about superintelligent AI but social engineering continues to be by far the biggest attack vector for digital infrastructure. And it’s being made worse by companies continuously cutting costs in areas like support. The call center employee making third world minimum wage doesn’t give a shit who the real owner of the domain is. They want to end the call quickly and get 5 stars from the customer on the feedback form. I have made it a point to move off services that force SMS-based 2fa for this exact reason. Recently even changed banks because of this. |
|
For example, try to social engineer a sim swap attack or number port attack with sim lock and port lock turned on. Won’t work. These attacks were super common just 5 years ago, now they’re effectively dead in the US.
You have to technically make sure the customer service people can’t break security. If you give them the keys, you’re cooked. So put the keys in a vault and then cover the vault in spikes and a 5 day timer.