Skip to content

Social engineering

Cyber security Lesson 4 2:00 English narration · English + 中文 subtitles burned in

space play · ←/→ 5s · j/l 10s · f fullscreen · ,/. speed

Chapters

Transcript
Everything so far has attacked the machine. 到目前为止讲的都是攻击机器。
But the weakest part of a system is usually not the machine — it is a person, who can simply be asked. 但一个系统里最弱的一环通常不是机器—— 而是人,因为人可以直接被"问"。
Social engineering means tricking somebody into giving away a secret or an access they hold. 社会工程学指的是骗某个人交出他手里的秘密或权限。
No malware, no exploit, no code at all: just a convincing story. 没有恶意软件,没有漏洞利用,一行代码都没有:只有一个说得通的故事。
Two names get confused because their definitions differ by one clause. 有两个名字常被搞混,因为它们的定义只差一个从句。
Phishing: a fake message arrives, YOU click its link, and a fake site takes your password. 钓鱼:一封假消息到达,"你"点了它的链接,然后一个假网站拿走了你的密码。
Pharming: you typed it correctly — the real address — and you are redirected to the fake site anyway. 域名劫持:你输对了——输的是真地址——但你还是被重定向到了那个假网站。
Look at the first box of each and the distinction is obvious. 看一看两条流程的第一格,区别就一目了然。
Here is a real-looking message with its tells marked. 这里是一封看起来很真的消息,破绽都标了出来。
The sender's address is not the bank's — read past the display name. 发件地址不是银行的——别只看显示名字,看后面的地址。
It pushes urgency: act now or your account closes. 它在催你:现在就行动,否则账户关闭。
There are two spelling mistakes in four lines. 四行字里有两个拼写错误。
And the rule that beats all of them: a real bank never asks for your password, by email or otherwise. 而胜过以上所有的那条规则是: 真正的银行绝不会问你要密码,无论用邮件还是别的方式。
Two more need no computer at all on the attacker's side. 还有两种在攻击者那一侧完全不需要电脑。
Shoulder surfing is exactly what it sounds like: somebody watching over your shoulder as you type a PIN. 肩窥就是字面意思:有人从你肩膀后面看着你输 PIN。
And baiting is leaving an infected USB stick somewhere for a person curious enough to plug it in. 而"诱饵"是把一个带毒的 U 盘丢在某处, 等一个好奇到会把它插上的人。
The defence for all of it is the same: slow down and check before you click, type, or plug anything in. 对付这一切的防御是同一个: 在你点击、输入或者插上什么东西之前,慢一点,先确认。
Four things to take with you. 带走四点。
One: social engineering tricks the person, not the computer. 第一:社会工程学骗的是人,不是电脑。
Two: phishing needs you to click a link in a fake message. 第二:钓鱼需要你去点一封假消息里的链接。
Three: pharming redirects you even when the address is right. 第三:域名劫持在你输对地址时也会把你带走。
Four: check the sender and hover the link before you click. 第四:点之前先看发件人、先悬停看链接。
Now do the tasks below. 现在去做下面的题。

Log in or create account

IGCSE, A-Level & AP