Social engineering
Cyber security Lesson 4 2:00 English narration · English + 中文 subtitles burned in
Chapters
Transcript
Everything so far has attacked the machine.
到目前为止讲的都是攻击机器。
But the weakest part of a system is usually not the machine — it is a person, who can simply be asked.
但一个系统里最弱的一环通常不是机器—— 而是人,因为人可以直接被"问"。
Social engineering means tricking somebody into giving away a secret or an access they hold.
社会工程学指的是骗某个人交出他手里的秘密或权限。
No malware, no exploit, no code at all: just a convincing story.
没有恶意软件,没有漏洞利用,一行代码都没有:只有一个说得通的故事。
Two names get confused because their definitions differ by one clause.
有两个名字常被搞混,因为它们的定义只差一个从句。
Phishing: a fake message arrives, YOU click its link, and a fake site takes your password.
钓鱼:一封假消息到达,"你"点了它的链接,然后一个假网站拿走了你的密码。
Pharming: you typed it correctly — the real address — and you are redirected to the fake site anyway.
域名劫持:你输对了——输的是真地址——但你还是被重定向到了那个假网站。
Look at the first box of each and the distinction is obvious.
看一看两条流程的第一格,区别就一目了然。
Here is a real-looking message with its tells marked.
这里是一封看起来很真的消息,破绽都标了出来。
The sender's address is not the bank's — read past the display name.
发件地址不是银行的——别只看显示名字,看后面的地址。
It pushes urgency: act now or your account closes.
它在催你:现在就行动,否则账户关闭。
There are two spelling mistakes in four lines.
四行字里有两个拼写错误。
And the rule that beats all of them: a real bank never asks for your password, by email or otherwise.
而胜过以上所有的那条规则是: 真正的银行绝不会问你要密码,无论用邮件还是别的方式。
Two more need no computer at all on the attacker's side.
还有两种在攻击者那一侧完全不需要电脑。
Shoulder surfing is exactly what it sounds like: somebody watching over your shoulder as you type a PIN.
肩窥就是字面意思:有人从你肩膀后面看着你输 PIN。
And baiting is leaving an infected USB stick somewhere for a person curious enough to plug it in.
而"诱饵"是把一个带毒的 U 盘丢在某处, 等一个好奇到会把它插上的人。
The defence for all of it is the same: slow down and check before you click, type, or plug anything in.
对付这一切的防御是同一个: 在你点击、输入或者插上什么东西之前,慢一点,先确认。
Four things to take with you.
带走四点。
One: social engineering tricks the person, not the computer.
第一:社会工程学骗的是人,不是电脑。
Two: phishing needs you to click a link in a fake message.
第二:钓鱼需要你去点一封假消息里的链接。
Three: pharming redirects you even when the address is right.
第三:域名劫持在你输对地址时也会把你带走。
Four: check the sender and hover the link before you click.
第四:点之前先看发件人、先悬停看链接。
Now do the tasks below.
现在去做下面的题。