The Art of Intrusion
by Kevin D. Mitnick & William L. Simon
War stories that teach defense by showing you the attack — uneven, but the good ones stick.
- Status
- Read · September 2024
- Bought
- September 3, 2024
- For
- Security engineers who think in attacker terms · Backend/platform folks who want to feel paranoid · Anyone curious about the human side of breaches
The one-paragraph verdict
This is a string of interviews — phone phreaks, prison hackers, casino-beating gamblers — each ending with a short “how you’d have stopped it” debrief. The best stories are genuinely engrossing and the defensive postmortems are the most useful part of the book. The weak spots are real too: some chapters are thin, a few read as dramatized or unverifiable, and the specific exploits dated quickly. It is not a technical manual and never pretends to be. What survives is the pattern recognition — the recurring truth that the human layer fails before the firewall does.
Who should read it
Security-minded engineers and anyone who builds systems other people trust. If you threat-model for a living, the stories are a useful gut-check on how creative real attackers get. Skip it if you want current TTPs, exploit code, or a structured course — this is anecdote, not reference.
Where it earned its place
It rewired how I read my own architecture: every trust boundary now gets the “who would lie to cross this?” question. It is also just a good plane read — the casino and phreaking chapters are pure fun. No platform tie-in; it sits on the off-duty shelf and earns it.
Skip it if…
You want a rigorous, up-to-date security text or hands-on technique. The lessons are timeless; the specifics are 2005-vintage, and a credulous reader will overvalue the more theatrical stories.
[The Art of Intrusion on Goodreads]