Comment by rainonmoon
10 hours ago
Those were always my favourite episodes too! Enough to get into a career doing social engineering and physical intrusions. It's very tense! You're right to think it's insane; the nature of these jobs is that unlike most kinds of pentesting, very few people are aware that a test is occurring. We will sometimes bring a fake "get out of jail free" card to test the very thing you mention, whether people will actually verify out of band. I've been on jobs where we've been called out and they've checked our fake details and you see people's whole body language change in those moments between them figuring out you're not who you say you are and figuring out what they're willing to do about it. You absolutely see the thought "Do I need to hurt these guys? Are they going to hurt me?" go through someone's mind. It's never come to anything truly harrowing in my experience, professionalism and good communication skills go a long way, but they also can only go so far. It's much more common to have zero issues though, because as you can surmise, social engineering is extremely effective, so getting challenged at all is pretty rare.
No comments yet
Contribute on Hacker News ↗