Social Engineering Blogs

An Aggregator for Blogs About Social Engineering and Related Fields

The Truth About Deception Blog December 9, 2013

Not All Lies Are Equal

Not all lies are the same. And trust comes in different flavors too.

New research reveals that being lied to can increase trust, some of the time.

When someone tells a lie with good intent, trust increases. That is, if someone tells a prosocial lie, we tend to trust him or her more. We make ourselves more open and vulnerable to prosocial liars – this is called “affective trust.”1 We

Read more…


Filed Under: Uncategorized

The Influence People Blog December 9, 2013

Persuasion Advice from the Wizard of Oz

Sometimes it feels good to revisit our childhood. I had that experience the day after Thanksgiving as I watched “The Wizard of Oz” again. I did so because I enjoy the movie and the memories it brings back. I also felt like I might learn something from the great and powerful Oz. I wasn’t disappointed!Dorothy and her friends – the Tin Man, the Cowardly Lion and the Scarecrow – make their way to the Land of Oz because they all need something from the Wizard. The Tin Man wants a heart, the Cowardly Lion is looking for courage and the Scarecrow is hoping to get a brain.When it comes to persuasion we’ll focus on the Scarecrow. The Wizard tells him all he really needs is a diploma. Once the Scarecrow has it in hand all of a sudden he believes he’s smart. See for yourself in the YouTube video clip below.Now we all know someone handing you a diploma doesn’t make you smart anymore than wearing a black belt to work makes you a martial arts master. Even earning both of those prestigious things – a college diploma or a black belt in some martial art – doesn’t certify you as a genius or the next Bruce Lee. However, each does make you better off. I can only assume someone who earned a college degree is more intelligent for having gone through the four-year process. As a result of their hard work and earning a diploma they’re more likely to land a good job and enjoy success as compared to those who don’t have a college degree. Likewise, people who’ve earned a black belt should be much more capable of defending themselves should the need arise.  But there’s another benefit. Having a diploma, black belt or some other certification can make you more persuasive. And the more difficult or rare your certification, the more impressive (i.e., persuasive) it is. That’s the principle of authority in operation. For example, did you know in 2005 more than 85% of United States citizens had a high school diploma but only 22% had a bachelor’s degree? Of course, getting a degree from a prestigious university will carry more weight than a more run of the mill school. After all, if you hear someone has a degree from Harvard or Yale you’re impressed, aren’t you? The exclusivity of a degree from a prestigious school is the principle of scarcity at work. And the more education you pursue (MBA, doctorate, etc.) the more impact it has.When it comes to a martial arts black belt there are no official population stats. Having taken taekwondo for many years I can tell you very few people get involved in the martial arts and the vast majority don’t put in the years it requires to earn a black belt. When you hear people have earned a second degree, third degree or more, you know they’ve been practicing their craft for many, many years. The more degrees, the more impressive from an authority and scarcity standpoint.So when people know you’re a college graduate, especially from a prestigious university, that gives you more credibility but a key is that people know what your credentials are before you attempt to persuade them. This is why speakers should always have a bio prepared for a third party to introduce them before they present.The same effect can be had prior to important meetings with a newer client. Having a bio prepared for someone (an associate of the person you’ll meet, your boss, a mutual friend, etc.) to send via email on your behalf gets your credibility established before the meeting.Here’s a powerful tip – you write the bio or email. That’s right, you write the bio or email then give it to the third party and tell them they can wordsmith it so it sounds like them. Never, ever, ever leave it up to the other person to write this on your behalf because they don’t know all you’ve done and accomplished. As you write the email it may feel like you’re bragging but it will sound perfectly natural coming from the other person.Another area you want to make sure is current is LinkedIn. Does your LinkedIn profile show your degree? How about your awards and certificates? Do you mention any in your summary? LinkedIn is your online resume and people are checking it out so make sure it’s the best reflection possible of you and your accomplishments.So here’s your take away. Work hard, do the things most people aren’t willing to do, and see them through to completion. Once you’ve done that and earned your diploma, certificate, award or some other acknowledgement of your accomplishment, make sure people know about it before you try to persuade. It’s a small thing but it can make a big difference when it comes to persuasion.Brian Ahearn, CMCT® Chief Influence OfficerinfluencePEOPLE Helping You Learn to Hear “Yes”.

Filed Under: Influence, Psychology, Science

The Security Dialogue Blog December 8, 2013

Social Media Investigations 101 – Are You Sure You Want To Post That?

Soooo…. You’ve been on Facebook a while and you’ve set your privacy settings to whatever new super-secret stealthy hidden mode setting Facebook has.  You probably also feel like none of your 400+ friends would ever tell anyone what you post. You look at articles about people posting things they shouldn’t going viral and you think “I’m so glad that’s not me. I would never do something like that.” I destroy that myth everyday at my job. In real life, I investigate leads in criminal cases which can aid my clients. A favorite place I go for these leads is social media.When I tell people I go to Facebook for leads, the first thing they like to say is “Well, you’re not going to find anything on me like that.” I’m polite so I smile and tell them “Probably not.” Of course, I’m lying. If I’ve told you that, this is where you’re probably feeling a little uneasy. Let’s be clear, if I don’t have an interest in finding something, I probably won’t find it. That’s not to say I can’t because I assure you I can.So, let’s breakdown how I might do a social media query. I won’t bore you with site specifics but I will address some things that are common throughout the social media investigations landscape. This is not to scare you. I am merely trying to inform you so you understand exactly what information you voluntarily give away.Disclaimer: For the experts: This in not all-inclusive and I’m aware of the many advances in social media investigations. This is mainly informative for those who may not know and to spark some discussion.  All others: Please check whatever jurisdiction for whatever legalities may exist for you.The best way to illustrate this topic is to assume you’ll be doing a search yourself. If you don’t mind being spooked, try this on yourself assuming you’re a complete stranger who’s only been given the task of obtaining whatever information exists on you in social media. I recommend creating your own “blank” account that you have no affiliation with to get started. When we get to associates, feel free to pretend and assume the worse about people on your friends list you haven’t seen or spoken to in some time. Start with a subject. Having a name (preferably a first and last name is good). I’ve done this with neither. More on that later.Put the name in the search box of the social media site you’re searching. This fruitful if you’re seeing if someone is on the site or if the profile is possibly “hidden” from searches. The latter requires for you to know the subject is actually on the site. While doing this, play around with nicknames or aliases. A personal favorite of mine are email addresses. I also use their most used username if I know it. I have also looked up last names only just to see if someone posts things to a relative’s profile.When searching Google, try to place quotations marks at the beginning and end of your subject’s name. Also, type in site:whatever-the-social-media-site-you-think-they-are-on.com/net/org/edu/gov. Novice searchers give up because the results are too many. This narrows it down quite a bit.Despite what you think, no name is too common for a determined investigator. There are other things than our names that differentiate us. For example, your name is “John Smith”. That’s too common of a name for some investigators. But what happens when I search for “John Smith” in Dayton, OH who is a police officer married to a woman named Ebony? If you’re the target, you’re not as anonymous as you thought.Search them by username and old phone numbers. Sometimes, this is all you have to go on. Do it. That username may be their most commonly used one for everything. This could lead to old social media profiles (a time machine treasure trove of forgotten pics, lifetime issues and events, contacts, etc.), photo-sharing sites they frequent, articles they bookmark (Pinterest), comments they’ve made on other sites (Youtube can be great for this stuff), and sites they don’t want anyone to know they frequent. Getting the username can be tricky. If I have a confirmed profile for them, I’ll take the username that is in the profile’s URL and then perform an “exact phrase” search on Google.I like to try the phone numbers search quite a bit. I’m not looking for an address neccessarily if it’s a social media investigation. Some profiles are only searchable with a phone number. Also people post their numbers on sites that don’t value privacy. For example, you run a shop that sells auto parts. As such, you belonged to a parts forum online. There you posted your number to get orders under a username I never knew existed. Not only do I have historical data on you possibly but I may also get a look at your posts there as well whatever I can dig up on this old username.If none of this proves fruitful, try a Google Image search. You may not be aware of this but Google now allows you to search by image. That means, I don’t need your name to find you on the Internet. Sometimes, I find people use the same photo for most sites they frequent. Perhaps, you’ll find a site with a picture you have and can dig up useful information such as other pictures, other usernames, and most importantly, associates.Associates are where the money is. Seriously, most people assume, wrongly, their Facebook friends feel the same way they do about things or they feel some impunity with what they post to their audience. In some cases, this may be true. However, I can guarantee it probably is not. Finding associates can be tricky if you don’t know much about your subject. Hopefully, Google will help you out here. If not, I recommend spending the $19.95 to use people-search sites like Intelius or Spokeo. This should give you a list of names of people who either know your subject or lived in the same area as him. Also, try Classmates.com. Someone went to high school with your subject and I bet you they’re still on their Facebook friend’s list. Another feature of some site’s search engines is the suggest friend’s list. If you’re friends with their friends, social media sites like to let you know and ask if you want to be your subject’s friend. Of course, you don’t. But this provides with that profile you’ve been looking for or at least one of them.Old friendships are tricky. We think the people who have known us the longest have our best interests at heart. Let me assure, some of them don’t. Most people trust these folks with lots of personal information, when they go on a tirade or a rant. The simple truth is if someone has it in for you, they can voluntarily give anyone access to whatever you share with them online.This young lady thought she was being “funny” outside of Arlington. Several of her “friends” didn’t think so. Be careful what you “like”. People wrongly assume the pages they like or the comments they reply to on someone else’s page is somehow protected. Yeah, that is totally wrong. It is protected ONLY if they have set themselves up with the strictest privacy settings. Many times, a person’s “likes” can reveal about themselves even if an investigator can’t see anything else. A great example are Facebook Groups which advocate violence or are sexually explicit. Unfortunately, people forget to hide what pages they “like” and it suddenly has some bearing on something they never imagined it would.Search for a name in a foreign language. I see you laughing but I once had someone hide their profile by using another language to hide their name. It’s a great idea but as I ran out of options, I went to Google Translate and entered the subject’s name from English to Korean. Suddenly, her profile appeared.Search their friends’ friends list. Some people hide in plain sight. You may be searching for the right subject but entered the wrong letter. A friend’s friends list will probably have the name as something else.Search EVERY PHOTO, LOCATION TAG, EVENT SIGN-IN, etc. Sometimes, the information we seek is in places we dismiss as being “dry”. Look through EVERYTHING. Trust me. This alone can give you more associates, state of mind of your subject, places they’ve been or frequent, events they’ve been or locations they can be expected to be at, and all the drama that comes with social media picture posting.When you’ve found what you’re looking for, archive it. This sounds easier than you think. Grab your smartphone and take a picture of your screen where the information is. People trust screenshots more than they do a link they can click.Do this exercise on yourself and assume your current or future employer, spouse, child custody judge, friends, family, and others are doing the same. Those who get their 15 minutes of fame from poor Facebook posts never seem to think they’d get turned in by their “friends”. Also, here’s a tidbit – if you’re posting information you shouldn’t, never exclaim “I don’t care who sees this.” I GUARANTEE you will.*Some places I like to go to search for social media investigation querieswww.spokeo.comwww.pipl.comwww.linkedin.comwww.facebook.comwww.twitter.comwww.google.comimages.google.comwww.whitepages.comwww.intelius.comwww.blackbookonline.infowww.topsy.com *You’re not getting all of my trade secrets

Filed Under: Investigations, OSINT

  • « Previous Page
  • 1
  • …
  • 361
  • 362
  • 363
  • 364
  • 365
  • …
  • 561
  • Next Page »

About

Welcome to an aggregator for blogs about social engineering and related fields. Feel free to take a look around, and make sure to visit the original sites.

If you would like to suggest a site or contact us, use the links below.

Contact

  • Contact
  • Suggest a Site
  • Remove a Site

© Copyright 2025 Social Engineering Blogs · All Rights Reserved ·