Je suis tombé par hasard ce matin sur 2 concepts intéressants (aka “common trick”), le “social engineering” et le “shoulder surfing” qui ont pour objectif commun de s’approprier vos mots de passe à votre insu :twisted:.
Le social engineering:
A classic social engineering trick is for a hacker to send email claiming to be a system administrator. The hacker will claim to need your password for some important system administration work, and ask you to email it to him/her. (…) it’s possible for a hacker to forge email, making it look like it came from somebody you know to be a legitimate system administrator. Often the hacker will send this message to every user on a system, hoping that one or two users will fall for the trick.
Le shoulder surfing:
This simply means that somebody looks over your shoulder while you type in your password. Sometimes it’s impossible to guarantee that nobody can see your keystrokes, for example in a crowded computer lab. But you should be on the look out for people looking over you shoulder for no good reason. If you’re suspicious of somebody, don’t type your password until they’ve gone. If you think somebody has seen your password, change it after they’re gone (use the command passwd).
Bon, j’ai compris, il ne faut plus faire confiance aux mails qu’on reçoit et installer des miroirs au bureau :razz:.
Tags:
login,
motdepasse,
password,
securite