Showing posts with label human biocomputer. Show all posts
Showing posts with label human biocomputer. Show all posts

Monday, December 17, 2012

A good social engineering article from the BBC

The Alan Woodward wrote a fairly good article for the BBC on the vulnerabilities of the human biocomputer. Ignore the pseudo-religious language in the introduction; this is good stuff.

The phenomenon of "social engineering" is behind the vast majority of successful hacking.
This isn't the high tech wizardry of Hollywood but is a good, old-fashioned confidence trick.
It's been updated for the modern age, and although modern terms such as "phishing" and "smishing" are used to describe the specific tricks used, they all rely upon a set of human characteristics which, with due respect to Hieronymus Bosch, you might picture as the "seven deadly sins" of social engineering.
Apathy:
To fall for a confidence trick, or worse, we assume others "must" have taken the necessary steps to keep us secure.
Sadly this leads to a lack of awareness, and in the world of the hacker that is fatal. When we stay in a hotel and we programme our random number into the room safe to keep our belongings secure, how many of us check to see if the manufacturers override code has been left in the safe?
It's nearly always 0000 or 1234 so try it next time.
Curiosity:Humans are curious by nature. However, naive and uninformed curiosity has caused many casualties. Criminals know we're curious and they will try to lure us in. If we see an unfamiliar door appear in a building we frequent, we all wonder where it leads.
We might be tempted to open it and find out, but in the online world that might just be a trap waiting for an innocent user to spring it. A colleague built a website that contained a button that said Do Not Press, and was astonished to find that the majority of people actually pressed it.
Be curious, but exercise a healthy degree of suspicion.Gullibility:It is often thought of as a derogatory term, but we all suffer from this sin. We make assumptions.
We take others at face value, especially outside of our areas of expertise. Put a uniform on someone and we assume they have authority. 
Give an email an official appearance by using the correct logo and apparently coming from the correct email address, and we might just assume it's real, regardless of how silly its instructions might be.
All of this can be easily forged online, so make no assumptions.Courtesy:We quite rightly all teach our children to be polite. However, politeness does not mean you should not discriminate.
If you do not know something, or you feel something doesn't feel quite right, ask. This principle is truer than ever in the online world, where we are asked to interact with people and systems in ways with which we are quite unfamiliar.
If someone phones you out of the blue and says they are from your bank do you believe them? 
No. Phone them back.
And by the way, use a mobile phone as landlines can remain connected to the person who made the call in the first place and so whilst you might think you're phoning the bank on a valid number you're just talking to the person who called you.Greed:Despite what we'd like to think we are all susceptible to greed even though it might not feel like greed.
Since its inception, the very culture of the web has been to share items for free.
Initially this was academic research, but as the internet was commercialised in the mid-1990s, we were left with the impression that we could still find something for nothing.
Nothing is ever truly free online. You have to remember that if you're not the paying customer, you're very likely to be the product. In the worst case, you might find that you have taken something onto your machine that is far from what you bargained for.
Many pieces of malware are actively downloaded by owners unaware that the "free" product contains a nasty payload, even if it also appears to do what you expected of it.Diffidence:
People are reluctant to ask strangers for ID, and in the online world it is more important than ever to establish the credentials of those whom you entrust with your sensitive information.
Do not let circumstances lead you to make assumptions about ID.
For example, if someone from "IT support" calls you and asks for your password so they can help fix your problem, how do you know they haven't called everyone else in the building first until they found you who has really got a problem?
This is a well-known attack. If someone has a problem with proving who they are, you should immediately be suspicious.Thoughtlessness:Thinking before you act is possibly the most effective means of protecting yourself online. It is all too easy to click that link.
Stop.
How many of us when reading an apparently valid link in an email would bother to check whether the link is actually valid or whether instead it takes you to a malicious site.
It's horribly easy to make links look valid so try hovering your cursor over the link for a few seconds before clicking to see what the real link is: the true link pops up if you give it a moment.
As cynical as it may sound, the only answer is to practise your A-B-C:
  • Assume nothing
  • Believe no one
  • Check everything
With more Christmas shopping expected to be done online this year than ever before, you should watch out for those that would exploit the deadly sins.
Don't give criminals the chance to ruin your holiday season, and remember that a little bit of paranoia goes a long way online.
Alan Woodward is a visiting professor at the University of Surrey's department of computing. He has worked for the UK government and consults on issues including cyber-security, covert communications and forensic computing. 

Source

Now, I wish there had been a bit more cog-sci in this article and a bit less of the forced comparisons to medieval eschatological literature, but all in all it's pretty good.

Too bad nobody will follow it. 

Monday, September 26, 2011

Exploits in the Human Biocomputer: Buffet Edition
















Exploits in the Human Biocomputer (NLP Edition)


I suspect that NLPers have their own name for the Doctor Fox effect. That said, I don't see the point of saying something so precisely meaningless in terms of propaganda, except when preaching to the choir. There is something to be said for having confidence that if you are ever caught with nothing to say you can say nothing quite well and convince everyone you said what they wanted to hear, however. Perhaps I will do this the next time I give a presentation.

Friday, August 5, 2011

Exploits in the Human Biocomputer (digest)

So, I haven't been around too much. But, I've run into several interesting things for my Unpatched Exploits in the Human Biocomputer series. Time for a digest edition.








On the subject of imposition of order (a subject very close to my heart) we have some scientism:



and some content-free narrative literature:



On the subject of subliminal messages and the use of priming, The Language Log has an excellent article that references several studies on the subject. There is also this post there, relating to the results of lacking audience-awareness, though that post relates more closely to my obsession with Project Xanadu (and, by extension, the use of appropriate rather than standard user interfaces) than to cogsci.

In fact, there are several recent Language Log posts that belong here: the abuse of empathy reflexes in persuasion and the joys and errors of computational linguistics have both been mentioned recently. I have expanded upon the paragraph length analyses in the above post.

The so-called 'nym wars' should yield the material for a possible pseudonym-vs-anonym post in the future.

Saturday, May 7, 2011

Sublim experiment rundown

Back in the day (2006 or 2007), after several years of experimentation, I coauthored a document about the use of visual subliminal messages (specifically those produced by the xscreensaver package's xsublim program) for cognitive enhancement. It hasn't aged terribly well, and I'm rather embarrassed now by the writing style, but every so often someone contacts me asking whether or not I have continued experimentation. The answer is yes. I figure now is as good a time as any to give you the run-down on my later experiments.

As a first note, I am not experimenting with subliminal advertising. If you are looking for something about subliminal advertising, rocketboom has a good video on the subject, after which you will require no other materials.

At the time of writing the original document, I had a model of the mechanism involving chain reactions of primed ideas. This may still be relevant, but there are other (more down-to-earth) attributes of the process with more literature within the field of cognitive psychology to back them up. While subliminal messages do not give a strong enough priming to significantly influence behavior in the context of advertising (or rather, they don't have the property claimed of homeopathy: subliminals are not more powerful the less they are observed), subliminal messages have been shown to affect the sense of familiarity. In situations where unfamiliarity with terminology, wording, or notation is a major stumbling block, being subliminally primed with the terminology in question can act as a gentle introduction, making the terminology no longer seem arbitrarily difficult and frightening. By producing a false sense of familiarity with the subject matter, the subject matter seems easier to pick up.

Another idea (which is strongly influenced by the excellent book The Art of Memetics) is that mental blinders (and other psychological biases that prevent the absorption of unfamiliar or conflicting information) can be modeled as the defense mechanisms of dominant memeplexes. These memeplexes subvert, assimilate, or deny newcomers since new ideas can compete with the old ones. Subliminal messages allow slow and subtle subversion by all memeplexes, regardless of whether or not they conflict with existing ones. As a result, use of subliminals can decrease the likelihood of decisions being unduly biased by unseen socially reinforced heuristics, so long as documents whose dominant underlying assumptions differ conflictingly have their words primed.

So, above we have some new models for the mechanism of action. Furthermore, new attributes have been discovered.

The physiological effects of sublims are highly dependent upon the novelty of the content. A single static document of arbitrary length will quickly cease to be enough for sublims, eventually giving none of the symptoms at all. As the use of sublims increases, necessary novelty does not increase linearly but exponentially. I currently use more than twenty gigabytes of static plaintext as a small part of my sublim input, balanced out by semi-static input (fortune databases), significantly more dynamic input (mostly via the random page feature in mediawiki installations), and less structured 'noise' input (text generated from markov models of other documents, text generated by piping other inputs through rhyme generators and other filters, text generated using context-free grammars). Too much novelty (trying to sublim with a four gigabyte video interpreted as ascii text, say) is not physiologically pleasant.

Sublims have different effective novelty ranges given different mental states. Stimulants appear to raise the required novelty level. Depressants appear to lower the maximum novelty level, but occasionally they cause the sublims to have absolutely no effect. Binaural entrainment at theta range frequencies appears to maximize the physiological effects for as long as the entrainment is occurring, but when the pattern stabilizes the physiological effects disappear.

Finally, there are a few technical updates.

Xsublim is no longer maintained by the xscreensaver project, and if you install a modern version of xscreensaver xsublim will not be installed. The last time I checked, the xsublim source was part of the source tarball but could not be trivially coaxed to compile. I have been using an old binary copied from an earlier release.

I have used the xosd package to write a clone of xsublim, called asublim. It does not operate precisely the same way. Where xsublim caches the full run of the program from which it takes its input before displaying anything, asublim caches each space-separated token smaller than 512 bytes (and cuts those larger into 512 byte pieces) and displays them in real time. As a result, asublim starts more quickly but is also more sensitive to load fluctuations. When I have used it, the asublim program itself is significantly slower than most of the programs feeding it, and so I have not had pipe underflows or noticeable delays. Asublim does not currently have support for the various command line options that xsublim supports, though support for most of them can be implemented. Asublim also has a few glitches: the self-erasing feature appears to operate differently from xsublim's implementation, and so on programs (such as firefox) that are slow to redraw their window bitmap there is a tendency for already erased tokens to obscure the contents of the canvas. I have not duplicated this problem on anything other than firefox.

If you have found this post by researching the terms found in the original Infornography document, please post your comments here rather than looking me up.