Book review: Social engineering can expose your company secrets: case Kevin D. Mitnick

I love books and one of the books that I remember reading years ago was the book by Tsutomu Shimomura and John Markoff “Takedown: The  Pursuit and Capture of Kevin Mitnick, America’s Most Wanted Computer Outlaw-by the Man Who Did It”. This book came out in mid-90’s and as I was already then in software business, I was interested in to learn more about the mindset of hackers and Kevin D. Mitnick was at the time the most known.  At the time, I do not remember learning anything about Social Engineering but having read the latest book “Ghost in the Wires: My Adventures as the World’s Most Wanted Hacker” by Kevin Mitnick and William L. Simon, it became obvious to me how vulnerable humans are in revealing secrets to strangers without really thinking too much about it.

This book brings an intriguing perspective to what went on in Mitnick’s life and what makes it even more interesting is to see the other side of the coin and the comments that Mitnick makes about both Tsutomu Shimomura and John Markoff. According to Mitnick, many of the claims that Markoff’s book brings to light are false and it is obvious that Markoff is not one of Mitnick’s favorite friends. Whatever the case, this book brings the dark side of being a fugitive, not being able to spend time with family and having to move continuously from one place to another based on how close the authorities were able to get to him. He describes how bad he felt when he let down his mother and grandmother and the grief he cause to them by continuing on this illegal activity.

The book has lots of detailed examples of the hackings that he did to companies such as Nokia, Motorola, Sun Microsystems etc. The examples of Nokia were especially interesting when he explains how he called Salo product development in Finland and asked a person to send source code by using social engineering tactics. This is something that people do not think about and especially in large organizations where people assume that the request is coming from within the company and not from a hacker that pretends to be something else that he/she really is. The book explains the different tactics that Mitnick used and I think this book should be a required reading for any information system student or person that works within the technology field. It explains that the biggest threats in security might not be coming from weak security systems, but from the weakness of humans working in organizations. Mitnick knew the lingo and used this as a way to convince the other side on the telephone to do what he wanted. This is what social engineering is all about.

When reading the book, Mitnick claims that he was never after money or wanting to cause damage to any organization. He did hacking because of the challenge and I guess boredom. What was also obvious is that his friends that he was hacking with turned out to be not his friends as they became informers to get Mitnick prosecuted. I am not sure why Mitnick decided to spend a big part of this life having to worry about being arrested, but I guess many things in people and our lives can’t be explained. Mitnick also includes other famous hackers in his book such as Kevin Poulsen that spent time in prison and also wrote a book “Kingpin: How One Hacker Took Over the Billion-Dollar Cybercrime Underground”

If you want to read about Mitnick’s side of the story, I think this is a good book to get started.

“Stop thinking the world is a just place” says Jeffrey Pfeffer in his brand new book Power: Why Some People Have It and Other’s Don’t

I admit. I am a “bookaholic”. I write books and I love to read and buy books. I get inner strength from them and my mind gets nurtured with new ideas that I can dwell during the days when time permits as well as during my numerous world travels like the long flights across the Atlantic or in the continental USA.

Sometimes I am lucky to find a book that I know will make a difference in my thinking or will impact the course of my life. It is not always that much about the content; it could be a sentence, a chapter or a thing that I have completely ignored. I gave an example of this in my latest book Boldly into the World (in Finnish: Rohkeasti maailmalle – Onnistu liike-elämässä ja ihmisenä) how my life was chanced 15 years ago by reading a book while living in my native Finland. I think I have now run into a book that will make a difference in my thinking.

A few days ago I downloaded a sample version of Jeffrey Pfeffer’s book Power: Why Some People Have It and Others Don’t and my initial thought was that “yet another book about leadership for power-hungry people”.   It turned out to be a misconception of great proportions and after reading a few pages, I could not put down the book. Mr. Pfeffer has written other bestselling books in the past like What Were They Thinking?: Unconventional Wisdom About Management and he is a professor at Stanford University Graduate School of Business.  

The headline/subject in this blog-entry is “Stop thinking the world is a just place” is directly from Pfeffer’s book and I selected it as it brings well together the themes that I have dwelled in my first two books published by Talentum. The world is not fair and we need to be the ones in charge of our destiny. Think back of all of the events throughout your career when everybody else knew much better what you should be doing and you kept fulfilling the expectations of your ecosystem, not what you really wanted to do. Breaking from you’re the expectations from your surrounding network and doing what is the right thing for you to do is what you should strive towards. There are always plenty of naysayers around you that will break down your dreams and give reasons why not to do something.

These people are usually also the ones that can’t see outside their own framework that is typically built not to take risks and play safe when it comes to careers and life. How many people have you seen around you that don’t have the guts to say the way it is, but instead agrees on anything, even if it is stupid? Have you ever played with the thought that you might not live longer than a few months? Are you living the way that fulfills your own expectations and makes you happy?

People tend to push their dreams and hopes to the future by having an autosuggestion engine humming. This engine will generate all of the reasons why one should not enjoy things until retirement. Once retired, we can start living our lives and enjoy it. But what if you do not reach retirement and die earlier? Wouldn’t that be wasting your life? Isn’t it smarter to enjoy every day of your life and try to live a life that gives you purpose and that your job gives you some type of fulfillment?

I have tried to live my life by taking steps, breaking barriers in my own thinking but it has not always been easy. We struggle with ourselves to break from the known towards the unknown and that is only human. However, without doing these steps, I would not be writing this blog entry far away from my own native country and living the life of an entrepreneur. There were people that told me that I should not leave my native country and that it would be too dangerous and that I risked my own career. In retrospect, I think it was the other way around.  My staying stagnant in a safe environment without real challenges might have led to undesired results in many ways, including having a job that I would not enjoy.

We tend to think that if we work as good soldiers, the reward will eventually bring us fame and fortune, but unfortunately the research does not back this up at least when reading Pfeffer’s book. Each one of us has to take care of ourselves and during my 20+ years in software industry, I have seen many cases where good work and performance has not led to expected results from a career perspective. The idea and assumption of people to think that the world is a just and fair place and that everyone gets what he or she deserves and that the good will come as long as we work tirelessly. Pfeffer concludes about the fairness of this world as follows:

As soon as you recognize the just-world effect and its influence on your perceptions and try to combat the tendency to see the world as inherently fair, you will be able to learn more in every situation and be more vigilant and proactive to ensure your own success.

Based on Pfeffer’s book, people usually rank themselves much higher in skills than is the reality. We tend to think more about ourselves and we also like to push negative things aside to protect our self-esteem. We are also tempted to be surrounded by yes Sayers as they are not threatening our egos and we do not want to listen to the reality. For us to learn we need to get into different situations and even if these situations are not desired, we will learn from them and we might become stronger in future. If we collect likeminded people around us, we will never grow as human beings.  It is the same if you are the best in your ice hockey team. How are you supposed to grow as player if you are the top player and have nobody to look up to?

I run to similar thoughts in the excellent book Superconnect: Harnessing the Power of Networks and the Strength of Weak Links that explained clearly why strong links are not necessarily always good for our career building and life. If we all try to socialize with our strong links (family, close friends), we will never get outside our own comfort zone as we pretty much know what the world and world view is when collaborating with strong links. However, when we run into weak links (friends of friends etc.), there is a greater opportunity to run into an opportunity or idea that is outside your own sphere of influence and knowledge. I have tested this in my numerous workshops around the world by asking participants whether strong or weak links have had the most impact in their lives. The answer has been almost always that weak links have had the biggest impact. How about you? Is this also your experience?

 Frans Johansson explains extremely well what it means when two different domains/skill sets meet in his excellent book Medici Effect: What Elephants and Epidemics Can Teach US About Innovation. Johansson argues that real innovation breakthrough will come when two diciplins are combined like physics with biology where two research areas innovate things that would not be possible with only one research area. I am a proponent of this and have had this as a founding idea throughout my career.

People are often their own worst enemy. We like to feel good about ourselves and we want to maintain a positive self-image. We will do everything to keep our self-esteem preserved by either surrendering or putting obstacles in our way. According to Pfeffer, this is called for “self-handicapping” in the research literature. According to research, self-handicapping will impact negatively on people’s career and future.

We should have the courage to confess that none of us are perfect and that there are many areas that we need to develop to succeed in our objectives. I discussed about courage as part of organizational courage in my previous blog entry and I would be tempted to say that this reflects back to courage like courage to make a chance, courage to do what feels right and courage to change your life even if it feels incredibly frightening.  Pfeffer encourages us to get over yourself and get beyond your concerns and self-image and what others think about you. He concludes that others are far too busy to worry or think about you anyway as they are mostly concerned about themselves. Isn’t that so true when you think about it? We are mostly worried what others think about us which then makes us less decisive and afraid of making a change.

Pfeffer also concludes that you should not assume that your boss knows or notices what you are doing or have perfect picture of what you are about to do. Have you made sure that you manage up? Perfect execution of your tasks without your boss knowing about it might be the worst thing you can do specifically from promotion perspective. Do you understand what drives your boss and how you can get aligned with his/her objectives? What is it that you can do to make his/her career to move in the right direction? The topic “remember what matters to your boss” in Pfeffer’s book is very relevant and should be taken seriously. We are just humans and it seems that we think otherwise in many of the cases that I have seen and been part of myself. You should worry at least as much about your boss as you worry about your performance is the lesson that Pfeffer gives as a lesson based on the his research.

It was interesting to read in this book was the findings between job performance and career outcome. People with the belief that extremely good job performance automatically leads to great career outcome might be a fallacy of great measures. In fact, it has been documented that great job performance can in some cases even hurt the promotion of an individual. Why would this be the case? The way it is explained in some of the cases is that the superiors do not want to elevate a top performer as this individual would then suddenly stop promoting the superiors career. Think about your own career and the experiences that you have had. Have you had a boss that has become the obstacle in our career? Have your boss been afraid that your performance would impact adversely on his/her career. Do you know how to be politically savvy when dealing with power structures and career building? Have you made mistakes where you have blocked your own career at a company because you did not think through your actions?

Pfeffer’s book is well researched with relevant references to original studies/research and this is the way I have been taught to write my texts. A book with references gives an immediate larger sphere of knowledge for people that want to learn more of any specific topic in more detail. The book includes lots of practical examples of real-life events that help the reader to grasp the overall concept behind the well-researched topics.

In my upcoming blog entries, I will address the seven important personal qualities to build power that Pfeffer’s book offers as advice to its readers.  I highly recommend that you do yourself a favor and buy this book as soon as you can. It can give you advice that will pay off nicely in form of your career development and your life.

Why are you any different and why do some people inspire others?

Why is it that some people have the talent to inspire you and others just don’t?  We have all worked in companies with inspiring leaders, but we probably also have experiences working with people that have a negative impact on our future and well-being. I have experienced both. The first category of people makes you do unbelievable things and you are happy to do it and the second category of people will make your life miserable.

 The presentation by Simon Sinek explains well how some very well-known inspiring leaders have been able to get their troops to take huge jumps and get people to believe in the mission.  It usually boils down to communication and how you communicate to the world of why you exist, why your company exists and why you are different to the competition.  

What is exciting in the video is that Mr. Sinek explains most of our behavior and perception of things is based on biology, not psychology and how we as humans behave. I also have his book Start with Why: How Great Leaders Insipire Everyone to Take Action.

What we can all learn from leadership and the people that have made a difference is as follows:

1)      You can make a difference, no matter who you are as long as you behave and act in a manner where you can inspire others and as long as your motivations are based on good intentions.

2)      In the challenging economic times, the winners are the ones that get others to believe in the cause, whatever it happens to be.

3)      Look around you and ask yourself the question: do I believe in what I am doing and if I do not, why is that? Is it because you are not working with people that are inspired or is it that you are just too lazy to make a change? If either one of these turns out to be the case, I would recommend you to take action and change the course of your life

Our success is not only based on intelligence, but on the desire to do something that makes a difference. If you do not have the drive to inspire others and you are in a leadership role, you might want to figure out how you can change that.  If you don’t, you will not be successful as a leader in the long run as the people that work for you will either leave or try to figure out how to make your life hard to get rid of you. 

I am sure there are readers of this blog that think that my statements above are not based on true leadership mantra, but let me assure you, I have seen enough of cases throughout my career where good things turn bad due to uninspiring leadership. The old fashioned “hitting with the stick” leadership does not work anymore with the digital native generation.

Describe happiness question was unexpected to my interviewees

I spent at least 45 hours interviewing and transcribing the results in Microsoft OneNote (which is the best thing that happened to me as a tool, besides Microsoft Word) and I wanted the interviewee to focus on my questions, so I threw a question on them that they did not expect: “Describe what happiness means to you”. The second question was “Does money and happiness correlate in your mind?”.

Some of the interviewees had issues in giving a direct response to the first question, but most of the people said that happiness for them is “to live in balance with yourself, your family and your work”. I was very happy to hear that as my topic for my book is “how to balance your international life, career and family”.

The second question about money and happiness was clear to everybody. Money has not anything to do with happiness unless you are so poor that you have no money for food or clothing.

I told each interviewee to read the book The How of Happiness: A New Approach to Getting the Life You Want  from Dr.  Sonja Lyobomirsky. This book explains what is known about happiness from a research perspective and it is written in a very clear and format that anybody of us can understand.

How does an author find interesting topics to write about?

I am sitting in a tram in Helsinki, the sun is shining and I have a bunch of Russian tourists around me on their way to downtown Helsinki (city-center). Observing the environment, wondering how I can transform this environment to my new upcoming book is what I am thinking about. Businesspeople such as me have numerous days in different places around the world and this is something that I have decided to use effectively.

I bought a book (The Art of Creative Nonfiction: Writing and Selling the Literature of Reality)  to my Kindle DX from an author (Lee Gutkind) that describes the process of writing a nonfiction book; what goes in ones mind and what kind of life one can expect when living an authors life. I highly recommend this book for people that want to learn and have an interest to become an author.

 

[amazon-product image="51BJGXKN5CL._SL160_.jpg" type="image"]0471113565[/amazon-product]

Another one is from the worldfamous Stephen King whose book On writing explains how his life as an author feels and looks like. Both of these books can be found from Amazon.com.

[amazon-product image="51pLqiWyhLL._SL160_.jpg" type="image"]0743455967[/amazon-product]

Experiences of Harvard Business School by a student: Ahead of the Curve by Philip Delves Broughton

I have always been fascinated about university campuses, whether it is my own school (Helsinki School of Economics) or University of Paris, Sorbonne. These campuses has a magic into it and I find my own internal piece among the mostly beautiful buildings that they have. A British journalist Philip Delves Broughton has documented his experiences in Harvard Business School during his 2 year tenure. His experiences not only of the school, but also the teaching and other students has been narrated in the very interesting book “Ahead of the Curve” that is now available either as a Kindle book or as a hard copy. I own both versions. As I have been doing some book reviews in Finnish in my Finnish blog, I decided to share some of these video clips also in English. Stay tuned for more.