Several years ago one of the most well-known hackers Kevin Mitnick (see below) wrote a book on the art of deception, as the easiest way to get access to data and computer systems. Kevin Mitnick knows all there is to know about ways to breach into computer systems with hacker tools. Still he claims that hackers prefer the easy way of contacting the company they want to hack! As he quotes it in his book: “The Art of Deception” :

“Why should an attacker spend hours trying to break in, when he can do it instead with a simple phonecall” His book has numerous examples of how hackers misuse peoples will and interest in helping other people, and in particular colleagues. So if you as a hacker can impersonate a colleague you can get a lot of help – even the password to the person you have impersonated!!

If you want to secure your systems against deceptive attacks, you have to make your authentication process independent of normal human helpfulness and let an IT-based process conduct the authentication. Additionally you will even have a log of the process afterwards!

FastPass Facilitated Password Reset (FPR) is such a workflow, adding unique authentication steps to the process, where dynamic and contextual information is included. More information on FPR here 

On Kevin Mitnick from Wiley:

