Skip to content
Cover of The Art of Deception by Kevin D. Mitnick & William L. Simon
Security & Cyber Recommended

The Art of Deception

by Kevin D. Mitnick & William L. Simon

The case that your firewall's weakest port is a human being — made through story after story.

4.0 my rating
3.77 public avg
Status
Read · September 2024
Bought
September 3, 2024
For
Security engineers and blue-teamers · Anyone who designs auth, helpdesk, or access flows · Engineers who think security is only a code problem

Where it earned its place

The one-paragraph verdict

Mitnick’s thesis is brutally simple — attackers don’t break the crypto, they call the helpdesk and ask nicely. The book makes that case through dozens of pretexting scenarios told from both the attacker’s and the victim’s side, which is genuinely the strongest thing about it: you watch each con land and understand exactly which trust assumption failed. The weakness is that the scenarios are obviously fictionalized, repetitive by the halfway mark, and dated in their tradecraft (a lot of phone-and-fax). But the underlying pattern — authority, urgency, plausibility, a small favor — has not aged a day. [The Art of Deception on Goodreads]

Who should read it

Anyone who builds authentication, helpdesk, password-reset, or access-provisioning flows. If your threat model stops at the network boundary, this book will widen it. Skip it if you wanted a technical hacking manual — there is almost no code here, and that’s by design.

Where it earned its place

It changed how I think about Authelia SSO / OIDC. Strong SSO and MFA close the technical door, but the book is a constant reminder that the recovery and support paths around that door are where the real attack lives — so the account-recovery and helpdesk story matters as much as the token flow.

Skip it if…

You want current tradecraft or hands-on technique. The principles endure; the specific cons read like a museum piece. If anecdote-driven writing annoys you, the repetition will too.

#social-engineering#security#human-factors#infosec