{"id":1697,"date":"2025-02-07T13:13:12","date_gmt":"2025-02-07T20:13:12","guid":{"rendered":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/?p=1697"},"modified":"2025-02-07T13:13:14","modified_gmt":"2025-02-07T20:13:14","slug":"ethical-human-hacking","status":"publish","type":"post","link":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/2025\/02\/07\/ethical-human-hacking\/","title":{"rendered":"Ethical Human Hacking"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Note: this project is by Dina Board<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Humans, the weakest link in information security. An organization can implement the strongest and most advanced and robust security controls on their physical and logical systems and fortify their building. Yet, all it will take is an employee being manipulated, frightened, or simply indifferent to security protocols to let an adversary in. After all, humans are complex creatures, susceptible to manipulation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I remember my first red team engagement that involved human hacking \u2013 I was nervous and a part of me felt like I was doing something wrong. Technically, I was going to be manipulating innocent people who were not expecting to be used for information or access. It felt intrusive, even wrong. I had extensive conversations with my manager, and he explained that we strictly follow a series of best practices during our engagement to complete the project in an ethical manner. What are the practices? That\u2019s exactly what we\u2019ll uncover together during the presentation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Human hacking isn\u2019t new \u2013 people have been manipulating one another for centuries to get what they want. However, conducting human hacking campaigns to improve the security of an organization \u2013 that is a relatively new concept. No hacking campaign goes without consequences though; therefore, a system is required. Yet, what kind?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Since we\u2019re dealing with humans, which are inherently fragile, the system that we devise must be <em>ethical.\u00a0<\/em>Meaning, in line with an accepted set of principles of right and wrong to minimize harm.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">My presentation covers this exactly, I define what is ethical human hacking, examine why ethical testing is important and explore specific concerns associated with human hacking. You\u2019ll find common human vulnerabilities (your desire to be helpful may be detrimental) and we\u2019ll go through some real-life red team engagements that I worked on. You\u2019ll be able to criticize and see what worked (or didn\u2019t). I will explain some common tactics used and cover best practices (we\u2019re not here to hurt people) and then will let you have a go at some hypothetical red team engagements.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When you get to the real-life team engagements and then the hypothetical ones, take your time and think about how you would approach it. What would you have done differently? Why?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As you embark on this exploration with me, consider the evolving landscape of social engineering threats. With remote work becoming commonplace and digital footprints expanding, attackers have more avenues than ever to exploit human vulnerabilities. Understanding and ethically testing these weaknesses isn\u2019t just advantageous or \u201ca good idea\u201d \u2013 it\u2019s essential for the resilience of any organization.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Human hacking will forever be a relevant and important part of information security \u2013 for no matter how much technology we introduce, humans remain integral to its operation, and there is no way to bullet proof a human being from manipulation, cognitive biases, or suppress a human\u2019s desire to be helpful. I am particularly passionate about this topic, and hope to share some of that passion with you for this topic bridges the gap between human behavior and robust privacy protection \u2013human hacking tests the final weakest link: us.<\/p>\n\n\n\n<div data-wp-interactive=\"core\/file\" class=\"wp-block-file\"><object data-wp-bind--hidden=\"!state.hasPdfPreview\" hidden class=\"wp-block-file__embed\" data=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/02\/Board-Project-10120343.pdf\" type=\"application\/pdf\" style=\"width:100%;height:600px\" aria-label=\"Embed of Board - Project - 10120343.\"><\/object><a id=\"wp-block-file--media-1ccfd5ad-9334-4d38-afee-b029a242cae3\" href=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/02\/Board-Project-10120343.pdf\">Board &#8211; Project &#8211; 10120343<\/a><a href=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2025\/02\/Board-Project-10120343.pdf\" class=\"wp-block-file__button wp-element-button\" download aria-describedby=\"wp-block-file--media-1ccfd5ad-9334-4d38-afee-b029a242cae3\">Download<\/a><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Discussion Questions<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>What are the ethical boundaries of physical red teaming, and how can organizations ensure that assessments remain ethical and legal?<\/li>\n\n\n\n<li>Based on the case studies presented, what were the key security failures that allowed breaches to occur, and how could they have been prevented?<\/li>\n\n\n\n<li>How can an organization balance security awareness training with real-world red team exercises to improve overall security posture?<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Note: this project is by Dina Board Humans, the weakest link in information security. An organization can implement the strongest and most advanced and robust security controls on their physical and logical systems and fortify their building. Yet, all it will take is an employee being manipulated, frightened, or simply indifferent to security protocols to &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/2025\/02\/07\/ethical-human-hacking\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Ethical Human Hacking&#8221;<\/span><\/a><\/p>\n","protected":false},"author":654,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1697","post","type-post","status-publish","format-standard","hentry","category-uncategorized","entry"],"featured_image_src":null,"featured_image_src_square":null,"author_info":{"display_name":"Michelle Cheatham","author_link":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/author\/michelle-cheatham\/"},"_links":{"self":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts\/1697","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/users\/654"}],"replies":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/comments?post=1697"}],"version-history":[{"count":3,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts\/1697\/revisions"}],"predecessor-version":[{"id":1700,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts\/1697\/revisions\/1700"}],"wp:attachment":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/media?parent=1697"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/categories?post=1697"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/tags?post=1697"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}