Rantburg

Today's Front Page   View All of Fri 04/19/2024 View Thu 04/18/2024 View Wed 04/17/2024 View Tue 04/16/2024 View Mon 04/15/2024 View Sun 04/14/2024 View Sat 04/13/2024
2010-07-22 Home Front: WoT
Fictitious femme fatale fooled cybersecurity
Call her the Mata Hari of cyberspace.

Robin Sage, according to her profiles on Facebook and other social-networking websites, was an attractive, flirtatious 25-year-old woman working as a "cyber threat analyst" at the U.S. Navy's Network Warfare Command. Within less than a month, she amassed nearly 300 social-network connections among security specialists, military personnel and staff at intelligence agencies and defense contractors.

A handful of pictures on her Facebook page included one of her at a party posing in thigh-high knee socks and a skull-and-crossbones bikini captioned, "doing what I do best."

"Sorry to say, I'm not a Green Beret! Just a cute girl stopping by to say hey!" she rhymingly proclaimed on her Twitter page, concluding, "My life is about info sec [information security] all the way!"

And so it apparently was. She was an avid user of LinkedIn - a social-networking site for professionals sometimes described as "Facebook for grown-ups." Her connections on it included men working for the nation's most senior military officer, the chairman of the Joint Chiefs of Staff, and for one of the most secret government agencies of all, the National Reconnaissance Office (NRO), which builds, launches and runs U.S. spy satellites. Others included a senior intelligence official in the U.S. Marine Corps, the chief of staff for a U.S. congressman, and several senior executives at defense contractors, including Lockheed Martin Corp. and Northrop Grumman Corp. Almost all were seasoned security professionals.

But Robin Sage did not exist.

Her profile was a ruse set up by security consultant Thomas Ryan as part of an effort to expose weaknesses in the nation's defense and intelligence communities - what Mr. Ryan calls "an independent 'red team' exercise."

It is not the first time "white-hat" hackers have carried out such a social-engineering experiment, but military and intelligence security specialists told The Washington Times that the exercise reveals important vulnerabilities in the use of social networking by people in the national security field.

Ms. Sage's connections invited her to speak at a private-sector security conference in Miami, and to review an important technical paper by a NASA researcher. Several invited her to dinner. And there were many invitations to apply for jobs.

"If I can ever be of assistance with job opportunities here at Lockheed Martin, don't hesitate to contact me, as I'm at your service," one executive at the company told her.
Posted by tipper 2010-07-22 06:57|| || Front Page|| [8 views ]  Top

#1  Inspectors General should hire some REAL femme fatales to entice staffers at all levels, then fire the asses who get entrapped. This is pour encourager les autres.
Posted by Anguper Hupomosing9418 2010-07-22 08:45||   2010-07-22 08:45|| Front Page Top

#2 ...The funny part is what would have happened if just one of these people had Googled "Robin Sage".

Mike
Posted by Mike Kozlowski 2010-07-22 09:52||   2010-07-22 09:52|| Front Page Top

#3 operation honey-pot
Posted by linker 2010-07-22 22:39||   2010-07-22 22:39|| Front Page Top

06:55 Skidmark
06:53 Skidmark
06:53 Procopius2k
06:49 Skidmark
06:48 M. Murcek
06:48 Procopius2k
06:47 Skidmark
06:46 Skidmark
06:39 NN2N1
06:37 Frank G
06:37 Skidmark
06:35 Eohippus Smiter of the Faith3343
06:34 Skidmark
06:31 Grom the Reflective
06:30 Gloluns Turkeyneck4904
06:27 Skidmark
06:27 Grom the Reflective
06:26 Grom the Reflective
06:25 NN2N1
06:24 Skidmark
06:22 Frank G
06:20 Grom the Reflective
06:19 Skidmark
06:11 Skidmark









Paypal:
Google
Search WWW Search rantburg.com