|
|
|
|
|
by john_strinlai
4 days ago
|
|
the author explicitly said they had domain privacy on. so we know that the caller did not have the address information. and we can be certain that domain privacy wouldn't have helped in this case (because it didn't). https://news.ycombinator.com/item?id=49028611 >Convinced how? Often such things are via "knowing things" about the account holder. i have some experience with social engineering attacks (former infosec turned teacher) and it was probably a combination of: - caller confidence that they were the club owner/manager (because they were)
- offering/sending club-specific information that matched information on the site (flyers, pamphlets, etc.)
- "call the number on the website and i will answer it"
- an official college website page that had the caller listed as an owner/manager of the club
- some poor 20-something year old working in a hellish, windowless tier 1 tech support center
|
|