The Honey Stick Project
The Honey Stick Project started with a simple question: if you drop a USB flash drive in a public place, will someone pick it up and plug it into their computer?
The answer, as it turns out, is yes. Almost every time.
The Experiment
I loaded USB flash drives with a tracking mechanism - a harmless HTML file that would phone home when opened, recording the time, IP address, and basic system information of the computer it was plugged into. No malware, no data theft, no damage. Just a simple beacon to answer the question: did someone plug this in?
I then "lost" these drives in various locations: parking lots, coffee shops, conference venues, public transit stations, and office building lobbies. Each drive was labeled with something enticing - "Confidential", "Salary Information", "Photos", or left unlabeled entirely.
Why This Matters
Dropping USB drives is one of the oldest social engineering techniques in the book. Security professionals have been warning about it for years. Organizations include it in their security awareness training. "Do not plug in unknown USB drives" is supposed to be basic knowledge.
And yet, in our experiment, the majority of drives were plugged in within hours of being dropped. The labeled drives - especially "Confidential" and "Salary Information" - were accessed faster than the unlabeled ones. Curiosity, it seems, is a more powerful motivator than caution.
Results
The full results of Phase 1 are documented in the Phase 1 Results report. Key findings:
- Over 60% of dropped drives were plugged into a computer
- Drives labeled "Confidential" had the highest access rate
- Average time from drop to first access was under 4 hours
- Most access occurred on corporate networks during business hours
- None of the people who plugged in a drive reported it to their IT department
Lessons Learned
The Honey Stick Project demonstrates that security awareness training alone is not sufficient. People know they should not plug in unknown USB drives. They do it anyway. This suggests that our approach to security awareness needs to go beyond telling people what not to do - we need to help them understand why, and we need to make the secure choice the easy choice.
For organizations, the takeaway is clear: USB port controls, endpoint detection, and regular testing through simulated social engineering campaigns are not optional. They are necessary because human nature does not change just because you showed a PowerPoint slide about it.