R E L A T E D   C O N T E N T
ADVERTISEMENT

Two-thirds of workers fall for password honeytrap

Survey finds that it only takes a chocolate bar and a smile to get staff to reveal their passwords

IT Week Staff, IT Week 17 Apr 2007
ADVERTISEMENT

The majority of UK office workers will hand over their computer passwords in exchange for "a bar of chocolate and a smile", according to a new study from the organisers of the annual Infosec show.

The survey of 300 office workers and IT professionals was carried out at London stations and an IT trade show and found that 64 percent of the 300 people approached could be tricked into handing over their password in return for a flirtatious conversation and a free bar of chocolate.

The researchers used social engineering techniques to gain the information, initially asking the delegates if they knew what the most common password was and asking them what their password was. At this stage 40 percent of commuters and 22 percent of IT professionals told the interviewer their password.

If respondents initially refused to hand over their password the researcher then asked if it was based on the name of a child, pet or football team and began guessing possible passwords. At this point a further 42 percent of IT professionals and 22 percent of commuters divulged their password.

"What is most surprising is that even when the IT professionals became slightly wary about revealing their passwords, they were put at their ease by a smile and a bit of smooth talk," said Sam Jeffers, event manager for Infosecurity Europe 2007. "It just goes to show that we still have a long way to go in educating people about security policies and procedures as the person trying to steal data from a company is just as likely to be an attractive young woman acting as a honey trap as a hacker using technology to find a way into a corporate network."

See also:

Creative accounting can help land funds for IT security - ironically, compliance budgets may offer the best cover  28 Apr 2006
Firms are reluctant to roll out voice-over-IP systems until there are more safeguards  27 Apr 2006
Security specialists have announced a number of new tools to protect firms  25 Apr 2006
Firms must do separate risk assessments for different parts of their business, according to security experts  25 Apr 2006

All Hacking
Tags: Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Java, J2EE, Developer, Spring, Hibernate, London, city, Graduate. This is an amazing opportunity to join a successful city based team working at the cutting edge of development. My client is looking for strong Java/J2EE developers ... more >
| Aston Carter
E-Commerce, Greenfield, Agile, Java, J2EE, , JavaScript, SQL, London, City Graduate This is an exceptional opportunity for a talented Java, J2EE developer keen to work in a successful development team within arguable the best agile ... more >
| Rullion Computer Personnel Ltd
2nd Line Support Analyst London £35, 000 to £40, 500 My client is a global market leader in the Internet Applications Industry. The company is continually progressing and looking for areas of growth and this ... more >
| Rullion Computer Personnel Ltd
Security Architect / Information Security Specialist – St Albans - Global Leader - Shine At The Highest Level Security Solution Architect / Information Security Architect required by renowned blue-chip organisation offering the finest security projects ... more >
More job opportunities