Politely socially engineering IRL using sneaky magician techniques

Presented by Alexander Hogue
Tuesday 5:05 p.m.–5:20 p.m.
Target audience: User

Abstract

This talk is about using the same techniques a magician or pickpocket would use, but for social engineering and physical security mischief. We’ll exploit the wonky default settings of human brains for the sake of sneaking what you're doing past people. To a magician, your brain is probably running the wetware equivalent of Windows 95, so come along and get patched.

“hey but this has nothing to do with OSX 0days you’re a fraud” yeah well please come anyway it will be fun I promise <3.

Maybe you’re a sneaky red-teamer, and it’s time for you to put your building pass into the returns bin. Everyone is watching. They see you put the pass in the bin, and hear it land. They don’t even know they’re seeing something sneaky! Of course, you’ve somehow got your building pass hidden in your other hand. You put on your 1986 mirror-finish Aviators and walk out of the building just as it explodes in a fireball of best practices.

Let’s learn about: How pickpockets do their thing Why you don't even need to know pickpocketing and the previous dot point was a waste of your time Stealing stuff in plain sight (for example, keys off a table) Distracting someone juuuuust right so they leave their computer unlocked Manipulating attention, disguising, misleading, implying, and generally being a sneaky person Pretending we know psychology to explain how this all works * How to palm fifteen basketballs

We’ll really be skating on the line of breaking the magician’s code here so buckle up and remember to bring your wallets in your left pockets.

Presented by

Alexander Hogue

Alex is a kid with a laptop and a pocketful of memes. Currently he's a Security Something at Atlassian, which is a little bit like being an adult but with more ice cream. He makes dumb novelty websites as a substitute for getting out more.

©2016 Linux Australia and linux.conf.au 2017. Linux is a registered trademark of Linus Torvalds. Site design by Takeflight. Image credits can be found on our Colophon.