Digital or physical social engineering focus
Hola, this week I've been gathering a lot of data, both informal and formal - about social engineering attacks. A majority of the information I stumble across is about digital social engineering, which are the usual scams, such as phishing, catfishing, etc, through social media or e-mail, or links/misleading GUI's. But I think Tony had intended for me to scope digital social engineering out, and focus on the physical social engineering attacks that are aimed towards getting unauthorized access to a building/space, through tailgating or the like.
I've found a lot of information and I generally think everything is interesting. I think there's a lot to digital social engineering, and maybe a combination between digital and physical social engineering is the most effective type of this type of deception? I mean, what if the social engineer initiates contact through digital means, and gains trust through this type of media - and then proceeds with the attack physically?
Another concern I have so far is how much interaction design plays a part in this topic. I want interaction design to be the absolute centre, and I think there is a lot of interaction design to this type of social engineering. The user has to interact with the system in order to let a social engineer in. So what openings do I have there? Do I design the system so the social engineer too has to interact with the system? And how?
A lot of thoughts and a lot spinning in my head right now. I'm not worried, just thoughtful. I hope it'll turn out good.