Jayson E. Street is a guy with glasses and a warm smile. Of course, he doesn't look at all like the hacker stereotype that is often presented in movies (i.e. somewhat pale, and antisocial). But Jayson is a hacker and a hacker of people..

Street the master of deception: He is a social engineer, specializing in raising awareness of security issues and breaches that require a physical presence. He is honest, friendly, always smiling, and in addition to working in this field, he is also an InfoSec Ranger at Pwnie Express, known for his books and lectures around the world.
Information security professionals generally agree that people are the weakest link in security. Employees need access to do their jobs, so attackers are increasingly targeting them instead of the network to infiltrate the system.
A successful social engineer must have a broad set of skills. The most important seems to be the ability to understand the depth of human emotion. Reading people's faces, interpreting gestures, especially in a foreign country with a noticeably different culture, is a very difficult task that requires unlimited practice and skill.
Essentially, an experienced social engineer is the closest we have to the expression "mind reader." From a person's expression and the situation they are facing, they can create a scenario that gives them the advantage.
As Ernest Hemingway once said: “When people talk, listen completely. Most people never listen.” Well, that's what social engineers do.
Information is the most valuable commodity in today's world, and Jayson knows how to get it. During an interview with HNS, he vividly recounted how he managed to hack networks in the US, Malaysia, Jordan, Germany, Jamaica, France, and Lebanon.
His tools?
“I robbed a bank in Beirut, Lebanon, wearing a DEF CON leather jacket. I don’t speak Arabic or French, and frankly, I don’t fit in well in this city,” Jayson recalls.
As you can imagine, that didn’t stop him. He ended up on an employee’s office chair that allowed him to plug his Hak5 Rubber Ducky USB into his computer. By the end of his “visit” to the bank, he had the bank employee’s administrative ID, their password, and a smart card.
“Armed with this information I can find my way into their internal LAN.”
Of course, the bank officials were shocked by the lax security. They knew that if it was someone else with that kind of access, they could empty the vaults.
“I’m not the best coder or exploit programmer. I’m not and I’m never going to be that guy. But I don’t have to be if I have a screwdriver and can get the hard drive off your server. I don’t have to bypass the firewall if I can bypass the receptionist,” he says.
Jayson continues:
“Last year I managed to bypass the entire infrastructure of a high-end hotel on the French Riviera, wearing Ninja Turtles pajamas and walking barefoot.”
Confidence is key. During this walk he stumbled upon an unprotected entrance to the employee area, and within 30 minutes he was at the corporate office.
In these facilities after office hours, security was non-existent: desks, unlocked computers, open drawers..
“I never had a problem anywhere, even in government or financial institutions. In fact, a guard once helped me take the server out of the computer room and put it in my car,” he recalls happily.
Anti-social engineering
“I’m not trying to destroy companies. I’m making commitments to social awareness – my job is to educate people so they can understand,” he says.
Jayson actually seems to be trying to get caught. In his latest “attack,” he made suspicious movements on purpose to show off. In vain…
“I recently broke into a very secure building in New York City across from Ground Zero, wearing a T-shirt that said 'Your company's computer guy.'
After the breach, he went back to the building and explained to those involved exactly what happened and why. It's part of his job to raise awareness about security issues.
“Despite the outcome of my attacks, I have never encountered a stupid user,” he notes. “But I do see uneducated users who don’t have the proper training,” he says, explaining that security education should be an essential part of employee training.
His advice?
1. If you have a feeling that something is wrong, listen to the voice that tells you to react.
2. Organizations should have a designated person to call in case of doubt, or an email address where help can be reached. Every employee should know that if they see a suspicious person walking around, or receive a suspicious email, they can alert someone who will investigate what is going on. “Don’t approach the person, don’t open the attachment, notify security,” he advises.
This advice may sound simple, but Jayson's adventures around the world prove that even the largest organizations in the world still don't have basic security measures in place and don't have trained employees.
Hacking? People remain the weakest link in security.
