---
title: "EVENT REVIEW: Mitnick on Misdirection: Hacking as Close-up Magic"
description: "EVENT REVIEW: Mitnick on Misdirection: Hacking as Close-up Magic"
---

# EVENT REVIEW: Mitnick on Misdirection: Hacking as Close-up Magic

[Social Engineering](https://www.mitnicksecurity.com/in-the-news/tag/social-engineering), [Security Expert](https://www.mitnicksecurity.com/in-the-news/tag/security-expert), [Shodan Search](https://www.mitnicksecurity.com/in-the-news/tag/shodan-search), [Speaking Engagements](https://www.mitnicksecurity.com/in-the-news/tag/speaking-engagements), [Wannacry](https://www.mitnicksecurity.com/in-the-news/tag/wannacry), [Chief Hacking Officer](https://www.mitnicksecurity.com/in-the-news/tag/chief-hacking-officer), [Hacking](https://www.mitnicksecurity.com/in-the-news/tag/hacking), [Security Awareness Training](https://www.mitnicksecurity.com/in-the-news/tag/security-awareness-training), [Knowbe4](https://www.mitnicksecurity.com/in-the-news/tag/knowbe4), [Mitnick Security Consulting](https://www.mitnicksecurity.com/in-the-news/tag/mitnick-security-consulting), [Trojan](https://www.mitnicksecurity.com/in-the-news/tag/trojan), [White Hat](https://www.mitnicksecurity.com/in-the-news/tag/white-hat), [Kevin Mitnick](https://www.mitnicksecurity.com/in-the-news/tag/kevin-mitnick)

[ Mitnick Security| ](https://www.mitnicksecurity.com/in-the-news/author/mitnick-security)  05.23.2017| 2 MIN READ TIME

Information security experts routinely warn those they work with about the dangers of social engineering. One way to approach social engineering is to realize that it's magic, and by that we mean stage-and-street magic, not ritual magic. Like the conjuror who performs at a kid's birthday party, the social engineer relies on your trust, your expectations, and your susceptibility to misdirection.

**Kevin Mitnick**, who now runs Mitnick Security Consulting and also serves as Chief Hacking Officer for the anti-social-engineering training shop KnowBe4, is well known for his days as a black hat. The FBI eventually caught him in a famous and controversial investigation into wire fraud and other computer-related offenses. He did his prison time in the late 1990s, and was released in January 2000, with his access to information technology restricted to a landline phone as a condition of his supervised release. (That supervised release period is more than a decade in the past.)

Mitnick's rehabilitation and subsequent career as a white hat hacker are now famous. At the 2017 Cyber Investing Summit, he described his own path into hacking. It began, he said, with an early interest in magic, conjuring, and was fostered by a high school friend who was into phone phreaking, one of the ancestral forms of hacking where people would make free long-distance calls by whistling the right tone into a phone.

He demonstrated several hacks that bore an interesting resemblance to street magic, including theft of physical access card credentials using a remote card reader, microphone and webcam hacks, and the compromise of a workstation through a plausible social engineering attack. 

One of Mitnick's timelier demonstrations was the introduction of a Trojan into a patched, AV-equipped Windows 7 machine. Installation in memory makes it hard to detect an implant, he noted. "Any AV product can be bypassed." 

He showed a live instance of WannaCry, using a Shodan search to identify potential targets. The exploit he used employed a spoofed and quite persuasive GoToMeeting site. 

To avoid infection, Mitnick recommended "inoculating" personnel against attack by attacking them in training sessions. He also strongly recommended implementing well-crafted egress rules in the enterprise. 

A cautionary observation in closing. Many concerned with security are confident they can see through social engineering, and sometimes they're (we're) right—they (we) don’t believe the person sending the email is really the widow of a Nigerian prince, or that "Microsoft help desk" has really called us to help fix our MacBook. But, as they say, don't get cocky, kid. Spend some time watching card mechanics do their stuff. You probably can't tell how the ace of hearts got there, no matter how closely you look. If the social engineer is as good as the performer at Junior's birthday party, well, they might reel you in, too.

*Read this cool news snippet and get your daily does at the [source](https://thecyberwire.com/events/2017-cyber-investing-summit/mitnick-on-misdirection-hacking-as-close-up-magic.html).*

Source: [Cyberwire](http://https://thecyberwire.com/events/2017-cyber-investing-summit/mitnick-on-misdirection-hacking-as-close-up-magic.html)

# Related Resources

[![](https://www.mitnicksecurity.com/hs-fs/hubfs/Screen%20Shot%202020-08-14%20at%203.48.55%20PM.png?width=350&name=Screen%20Shot%202020-08-14%20at%203.48.55%20PM.png)

by Mitnick Security  | 08.16.2019  | 1 min

#### Advice from Kevin Mitnick Featured in the Wall Street Journal Op-Ed

Kevin Mitnick was interviewed by Mr. Maniloff who is an attorney at White and Williams LLP in Philadelphia and an adjunct professor at Temple University’s Beasley School of Law.

 Continue Reading

Knowbe4, Cybercrime, Kevin Mitnick, Wsj, Op-ed 

](https://www.mitnicksecurity.com/in-the-news/advice-from-kevin-mitnick-featured-in-the-wall-street-journal-op-ed)

[![](https://www.mitnicksecurity.com/hs-fs/hubfs/Images/Events/In%20The%20News/kevin-ku-w7ZyuGYNpRQ-unsplash.jpg?width=350&name=kevin-ku-w7ZyuGYNpRQ-unsplash.jpg)

by Mitnick Security  | 12.12.2018  | 3 min

#### 12 Ways to Defeat Two-Factor Authentication

Everyone knows that two-factor authentication (2FA) is more secure than a simple login name and password, but too many people think that 2FA is a perfect, unhackable solution. It isn't!

 Continue Reading

Speaking Engagements, Tw-factor Authentication - Roger A. Grimes, Chief Hacking Officer, Data-driven Defense Evangelist, Security Awareness Training, Knowbe4, Simulated Phishing Platform, 2Fa Solution, Kevin Mitnick 

](https://www.mitnicksecurity.com/in-the-news/12-ways-to-defeat-two-factor-authentication)

[![](https://www.mitnicksecurity.com/hs-fs/hubfs/Images/Events/In%20The%20News/simon-abrams-k_T9Zj3SE8k-unsplash.jpg?width=350&name=simon-abrams-k_T9Zj3SE8k-unsplash.jpg)

by Mitnick Security  | 11.26.2018  | 1 min

#### We Need to Talk About NIST’s Dropped Password Management Recommendations

Passwords and their protection are among the most fundamental, essential aspects of enterprise data security. They also make up the bane of most users’ relationships with their enterprise devices, res...

 Continue Reading

Speaking Engagements, 2Fa, Biometric Security, Two-factor Authentication, Fraud Prevention, Password, Password Management, Kevin Mitnick Security Awareness Training, Multifactor Authentication (Mfa, Password Reuse, Kevin Mitnick 

](https://www.mitnicksecurity.com/in-the-news/we-need-to-talk-about-nists-dropped-password-management-recommendations)