Much have been said and written about social media and social influence lately. I have personally contributed with several posts this year and I thought I had it pretty well covered. Until some smartass hacker asked me the following question:
“Ask yourself; can I achieve the same goal using influence without manipulation?”
Eric “Urbal” Maxwell
And let’s be honest: Can you? As for myself, I’m not sure. In fact, I’m not even sure if there is any difference! According to most dictionaries there is, but in practical terms? Still not sure…
I’ve been looking through a handful of different online dictionaries and found at least twice as many definitions.
Did you know that “manipulation” also can mean “skillful or artful management“? And that influence sometimes means “the power to persuade or obtain advantages as a result of one’s social status, wealth or position” You know…as in “corruption”?
INFLUENCE: “The capacity or power of persons or things to produce effects on others by intangible or indirect means.”
MANIPULATE: “To negotiate, control, or influence (something or someone) cleverly, skilfully, or deviously.”
You see the difference? (I still don’t…)
But this is where the hackers comes in.
In their latest newsletter, SocialEngeneering.org, Eric “Urbal” Maxwell share some fascinating insight on how this devious and feared group of hackers see it – and how they use it:
Influence comes in many different forms.
“Each type of influence can be used by itself or you can combine methods of influence for an even stronger reaction” Mr. Maxwell writes.
Reciprocity – “Can be summed up simply as the “golden rule” or treat others as you would like to be treated. When we give someone a gift, they naturally feel indebted to us. This feeling of indebtedness triggers reciprocity in your target and makes them much more likely to fulfill a request. “
Obligation –” The obligation principal is much like reciprocity, but instead of feeling indebted to someone and the need to return the favor, the feeling is generated from moral, societal, or legal obligation. For instance, saying “thank you” when someone says something nice is an example of obligation triggered by societal norms. How can we use obligation as a social engineer? Simply ask a question. Your target, when questioned, will feel an obligation to respond. It would be sort of weird if you asked someone a question and they just remained silent staring at you, right?.”
Concession – “Concession is the act of giving up something you want, or appear to want, so your target gives up something they want. This technique is used every day in sales. A good way to use concession is to start with a large request. Something much more than you actually want. When your target declines, you say, “ok, how about this…” and you ask for something smaller in scope. In reality, the final, small scoped request, was actually what you were after from the beginning. This is also referred to as Door-in-the-face technique.”
Scarcity – “We’re all familiar with scarcity in our daily lives. We witness it every day. Long lines outside tech stores on launch day of a new product, the Twinkie-pocalypse which sent the price of Twinkies into the stratosphere, and the mad rush of Black Friday shopping deals are all examples of scarcity in action. A social engineer can also use time, resources, and availability to achieve a desired outcome.”
Authority – “We are taught from a young age to respect authority and to listen to those in positions of authority over us. As a social engineer, positioning yourself as an authority over your target can aid greatly in generating compliance. Calling a call center employee, pretending to be a Senior IT member, or security guard will go a lot further in generating compliance vs. calling and masquerading as a janitor or mail clerk. Your vocal tone, clothing, body language, and job title are all things a social engineer can use to gain influence through authority.”
Commitment & Consistency – “Humans love consistency. It makes us feel good to interact with a consistent person because it conjures thoughts of stability, wisdom, and confidence. As a social engineer, consistency can be shown when formulating and executing your pretext. A mailroom clerk has no business calling and asking for a password, but an IT guy would. If you’re playing the role of a janitor, don’t wear fancy shoes or jewelry. Fit the part. Commitment comes into play by getting your target to say “yes” to requests. By getting the target to say “yes” to a request will increase the chances they’ll say “yes” to future requests.”
Liking – “The simple fact is, people like people who are like them. Expanding on that, people really like people who like them. Getting someone to like you is paramount and the importance can not be stressed enough. As a social engineer, we can project confidence, establish rapport, synchronise with your target (body language, speech rate, etc…), and communicate effectively. People will go to great lengths to do things for people they like.”
Social Proof – “Social proof is a very, very powerful form of influence. Social proof is where a group or person begins to think that something is good, acceptable, or OK based on the fact or idea that he/she thinks others view it as good or acceptable. Your target will feel pressure to comply if you make them think their peers agree or act in the way you’re requesting. One of our favorite examples of social proof is this elevator experiment. The participants get the target to stand in ways completely out of the norm while inside an elevator simply because everyone else is doing it.”
Influence and manipulation are obviously closely linked. Uncomfortably close, I would say.
The experts on human hacking, however, operates with a distinct difference:
The difference is when a social engineer uses manipulation, the goal is to introduce stress, anxiety, or discomfort to their target in an effort to achieve the desired goal
“It’s important to note that while manipulation tactics work, often very effectively, they introduce your target to negative feelings. These negative feelings make it extremely difficult to continue using the target as an information source. If your goal is to use your target as an ongoing source of reliable information, we would caution your use of manipulation. Use these tactics sparingly and only after careful consideration of the possible repercussions,” “Urbal” Maxwell points out.
Increasing Susceptibility – “Often times under stress, people will be more susceptible to suggestion and manipulation. As a social engineer, you will want to increase your target’s stress level by altering their emotions. Fear and anger are emotions that are good at increasing stress in a target.”
Environmental Control – “Environmental control refers to manipulating your environment under false pretexts that would cause your target to act in a way he or she wouldn’t normally behave. For instance, using a sexually attractive woman to seduce and perhaps engage in sexual activity (especially if the target’s married or a prominent member of society) with the target. The goal here is information extraction and even blackmail. This tactic is used extensively by spy agencies around the world.”
Forced reevaluation “Forced reevaluation is when you present your target with facts or “facts” that contradict their beliefs, rules, or instructions received. As an example, giving the illusion that you or your target may face negative repercussions unless they do something you request, even though the request goes against what they know is protocol.”
Removing Their Power – “Removing someone’s control, or their perception of control, removes their power. People want to feel in control and when they don’t, they often make wrong decisions. Making your target rush and forcing your target to make decisions without allowing them to think removes their control of the situation and increases their likelihood of compliance.”
Punishment – “The reality is, punishment or threat of punishment can be a great way to manipulate and influence someone, but it’s very unethical and we don’t promote use of this tactic. In some very rare situations, in a multi-person engagement, punishment may be used as a ruse to elicit feelings of sympathy in your target if your target witnesses your co-conspirator being punished.”
Intimidation – “Intimidation can be used in a lot of different ways. You can make your target feel that you have authority over them or that you’re in control of a situation. Looking busy or rushed can also intimidate people around you. Speaking forcefully, using piercing eye contact, as well as aggressive facial expressions are also ways to intimidate your target.”
“We usually recommend using influence over manipulation because it preserves your target for future use and prevents your target from feeling negatively,” sosialengeneering.org concludes.
Influence is one of the greatest things a social engineer can master. It does take time, but it’s worth it. I recently used reciprocity and scarcity to obtain a home address of a target by calling and pretending to be an employee of a gym my target attended. I told him he was randomly selected to win a free 1-year pass to the gym and that we already gave 9 away and he was the last one selected. He promptly gave up his home address to me as reciprocation for the scarce gifts. He even confirmed his birthday and last 4 digits of his credit card “on file”. What a nice guy!
Well, I don’t believe this nice guy stayed happy for a very long time – I assume he quickly felt rather negatively about the fact that he was conned by a con man.
And I suddenly got a hell of a lot more sceptical towards the so-called “influencers” of social media…
- How Much Social Influence Do You Need To Get Shot in the Head?
- What Makes Social Media so Influential?
- The Power of Social Media Is Nothing To Joke About
- Social Influence – The New Kind of Power
- EU To Spend $3 million on Training of Internet Trolls in Battle Against Bad Image
- World Soon To Be Run by Powerful Networks, US Intelligence
- How to Become a Social Media Influencer in Your Industry (blogs.salesforce.com)
- Influence Marketing: What’s Next? (business2community.com)
- Robert Cialdini explains the six ways to influence people – Interview: (businessinsider.com)
- 5 Ways to Reach Your Target Market Online (business2community.com)
All Human Rights Reserved (h) 2013