Showing posts with label physical security. Show all posts
Showing posts with label physical security. Show all posts

Friday, February 11, 2011

How the President's Security Motorcade Works

Jalopnik links to The Atlantic's Marc Ambinder's great article on how the Secret Service handles a significant event, including details of how the motorcade is organized and run. For those who think about physical security, this is an interesting read including a diagram of each vehicle and its role.

Friday, August 28, 2009

Defeating Acoustic Weapons

Wired covers the BBC show Bang Goes The Theory's designs to defeat acoustic weapons like the LRAD and other systems used to help protect cruise ships and for crowd control. As the article points out, simply defending from non-lethal systems may make users more of a target. Does this mean we'll see pirates attacking cruise ships while wearing giant fishbowl sound dampening helmets? Only time will tell...

Sunday, July 12, 2009

Self Defending ATMs: South African ATM Security

The Guardian describes South African ATMs designed to help combat the high incidence of ATM theft and destruction - over 500 in a single year. The article describes a variety of methods used to break into ATMs including explosives.

Pepper spray seems like a poor deterrent for thieves willing to use explosives to break into an ATM - but it may at least deter more casual criminals. Of course, the article notes that technicians have been amongst those who have suffered from the pepper spray, which they inadvertently activated. This also creates a hazard to those in the surrounding area, as pepper spray can spread and effect customers or others downwind.

In a highly hostile environment, self defending ATMs seem like an obvious step - but pepper spray may not be the best solution for others in the area. For now, law enforcement can look for the ATM using customers wearing gas masks.

Monday, July 6, 2009

Prison Makers: Escape Tools and Prison Ingenuity in Pictures

Mark Steinmetz has an amazing set of pictures of objects made by German prisoners. These should serve as a reminder that ingenuity and creativity can overcome many physical security precautions - and that even the most secure environment can provide tools.

Friday, January 16, 2009

Aggressor Mindset: Gothamist Interviews a Shoplifter


Gothamist has an interesting interview with a shoplifter who primarily targets grocery stores. Security professionals will likely find some of the statements familiar:

Where do you usually hit? I have a few rotations with Whole Foods, one of the main targets because I’ve figured out the structure, the infrastructure of the place.

You’ve figured out the infrastructure? Correct. I call them blind spots, there are a lot of blind spots.

While the shoplifter's value per theft is relatively low - $50 on average, the frequency is disturbing - two or more times a week. These small thefts can bleed an organization quickly, and are a real concern for their store security.

The shoplifter also offers advice for aspiring shoplifters:

Do you have any advice for aspiring shoplifters? Yes. First, choose your locations carefully, number one. Don't start right away, go there several times, walk around, get to know the people who work there, especially the ones who don't dress in uniform. Number two, the most important: get to know the camera system. You don’t want to be directly under the camera, you don’t want to be in front of the camera, you want to find blind spots, this is my technical term. Beyond the corner or the bottom reach of the camera.

Number three, always have an exit strategy. Meaning put things in different places, in your pocket or under your pants. Don’t do it right away. First you take the item and walk with it for a little bit. Then when the moment is right and the inspiration is correct, you put it in there. And you don’t run away right away, you stay and shop in the store for awhile until the energy comes down and then you calmly walk out. But the bottom line is don’t rush, don’t rush.

These are very similar to the plans a physical security penetration tester would prepare - but in this case, the theft is real.

Creative Commons Image credit gemteck1

Saturday, January 10, 2009

Sentry Safe's Unsafe Survey

Sentry, maker of a wide range of safes, requests some interesting information on their new safe owner's registration form. The form requests a surprising amount of information for a warranty registration form, including a number of details that would concern any security minded individual.


A few of the more sensitive bits of information that you'd be mailing off are:

  • Your address
  • Who you purchased the safe for
  • Where you will locate it (garage, basement, den, bedroom)
  • How many guns you own
  • How you stored your guns previously
  • How much you make
  • The other members of your household and their age
All of this is placed in a handy postcard sized fold out survey, ready to be mailed out. Individually, none of this information is particularly dangerous, however when taken as a whole, it provides a profile of a potential target - who, happily, gave you the model number and possibly the location of their safe!

Is this a huge threat? Probably not, but would new safe owners want to disclose the location of their safe, their income, and how many firearms they have? Probably not. Sometimes, security by obscurity isn't so bad.

Thursday, November 13, 2008

How Does Your ATM Uplink? Or "Physical Security Humor As An Installation Art Form"

A recent trip to the ATM resulted in an interesting receipt as the ATM crashed. Note the debugging information providing connectivity details for the ATM. In and of itself, this wasn't a real issue, but it was interesting to see, as the ATM appeared to be working properly.

Once this three foot long error receipt printed however, we noticed something more interesting about the ATM.


That deep dark space to the left of the ATM contained networking devices, including the network uplink. Since this is a third party ATM on private property, it was not connected to the building's network.


The devices appear to include some form of serial or parallel device, an ethernet to PCMCIA bridge with an AT&T wireless cell card, and an antenna with a magnet to provide reception from the top of the ATM. Sadly, the strongest physical security control here is the sheer amount of dirt present. Nothing would prevent a malicious (or curious) person from placing a hub between the bridge device and the ATM's link to capture traffic. The cell network card could even be taken and used quite easily. Best of all, the ATM has no coverage with a camera system, and is in an area that is open at all hours of the day.

A number of very simple actions could be taken to greatly improve the security of this ATM and its operations.

  • Secure the connectivity devices and network connections.
  • Install a security camera, either in the ATM or, better, with a vantage point to watch the ATM itself.
  • Prevent the device from providing debugging or error messages without entry of an administrative code or key.

Friday, October 10, 2008

ATM skimmers with SMS notification hit the scene

ZDNet has details on a $8500 ATM card skimming device that does automatic SMS notification when it captures data. Interestingly, the system also provides greater security for the person running it, preventing data capture and code based exploits. The article is worth a read if you're interested in the state of the art in skimming attacks.

Thursday, April 10, 2008

Good Disclosure Practices: RedBox announces a skimming exploit the right way

Skimming by placing a device on an existing reader to read credit card magstripes when they're swiped isn't new - it has been seen in the past at ATMs and other locations. It continues to happen, with varying levels of sophistication.

What is noteworthy is that Redbox reported it in a useful advisory including pictures of what the skimmers looked like - thus taking advantage of an issue to educate customers. They also show the attached blocks that help prevent identity thieves from attaching skimmers to the systems - addressing the question "what are you doing about it". The blocks are not a total solution, but they'll help prevent normal sized reader devices from being attached. Hopefully, monitoring the locations where the devices were found also leads to arrests.

Details of the discovery, and what the devices looked like can be found on Redbox's website at:
http://www.redbox.com/creditcardsecurity/

Wednesday, February 20, 2008

Blinding security cameras with IR LEDs

BoingBoing linked a translation of a German site today. The site shows a headband with an integrated IR LED that blinds security cameras. This is an interesting alternative to the old trick of blinding cameras with laser pointers, as it offers a means of creating anonymity that might not be noticed by others who saw you in person.

Monday, February 18, 2008

Learning from It Takes a Thief


The Discovery Channel's It Takes A Thief is an interesting method of advocating home security. For those who haven't watched it, the basic show format is that two hosts, both former burglars who have turned their lives around, first break into a house - with the owner's permission, then upgrade the house's security and retrain the owners before trying it again.

For those who have never participated in a physical security penetration test, this is a reasonable introduction to one form of penetration testing. If you're a security professional, or have physical security expertise, you'll probably note that their targets are selected for the wide variety of issues that they have, and that some of their actions as shown would make a security professional fail - things like entering the house without a written 'get out of jail free' card. You'll also note that while they make quite a few upgrades for physical security, there are often ways around the systems that are installed. If you're questioning that, read their security tips - their goal is to make the house a harder target than the rest of the neighborhood, not to make it invulnerable.

In either case, the families that are on the show do appear to get real security improvements and the impact that the show makes on their habits is real - at least in the short term. Let's hope that a year or two from now the show goes back to check how the participants are doing with their habits and whether their systems have continued to both be used and to function properly.

There are a few interesting things to note in comparison to what many of us might have considered: a penetration test by an electronic penetration testing company.

  1. The hosts select the owners by checking a number of houses in a given neighborhood, rather than the owners soliciting the testing. This remarkably similar to the unsolicited companies and individuals who look for vulnerabilities in software and websites.
  2. The owners are allowed to watch, but cannot respond to the event. In most penetration tests, organizations are encouraged to let their normal defenses respond as they normally would, typically with some level of cut-out to ensure that escalation doesn't cause damage or down-time. While one episode does see the police called on the host while he is robbing the house, the owners never come home and children or others are never in the house for the event.
  3. Technology, infrastructure, and process are reviewed and upgraded. This is very similar to the result of an electronic penetration test, however the hosts provide the upgrade. A model where the assessor does a risk assessment and determines the security improvements to be deployed (albeit, with the understanding that much of it is vendor driven based on advertising) is intriguing. You don't see a companies often doing this sort of publicity, but wouldn't it be an interesting marketing strategy?
  4. The homeowners watch video of the robbery as it happens. Typically senior members of an organization merely receive a report, as electronic penetrations are typically not as dramatic to watch. The impact of a home invasion and theft has a great impact on the homeowners, and the visceral feeling can't be easily replicated in a summary report of findings.
This is, at the end of the day, a live physical security penetration test. Identities are not fully disclosed, although people who recognize the homeowners or know their neighborhoods would be able to identify them and would be familiar with their security systems and their valuable possessions. That's an interesting potential issue, as the homes chosen thus far have typically had valuable possessions reaching into the hundreds of thousands of dollars.

I'll be pointing their home security tips out when I give talks on physical security - having a TV show example is a great way to reach my audience, and awareness at home is a great lead in to awareness at work.

Creative Commons licensed photo credit Flickr user Ben Scicluna

Friday, November 2, 2007

It's the simple stuff really

You know, it's a little frustrating to have taken exams with hundreds of questions about the obscurities and specifics of information security just so that I can prove that I know my stuff. I get these little letters after my name that impress the HR drones. That’s right I’m am information security professional! Banded together we geeks can enjoy a lively conversation on encryption for data at rest across disparate systems...“If we make cipher text on a system in an ASCII character set then transport it to a system using EBCDIC...” and so we digress. Ah, the upper echelon of geekdom.

However, it’s the simple stuff that makes or breaks your information security program. In the news recently was a decent account of the “Khaki Bandit” and his ability to walk right into a corporate setting and fill his bag with their laptops – and then walk right back out. Better yet, there’s an account here where a reporter walked into a major mail sorting facility in the UK and took up a position by simply claiming he already worked there.

In both incidents simple procedures could and would have stopped these individuals in their tracks. Sadly, neither was asked for proper ID nor escorted to their purported hosts. I’m not aware of any major loses or data breaches directly linked to these events, still both had the potential to wreak havoc on an organization and its clientèle. Not to mention its public image and brand trustworthiness.

Every organization should take a look at these stories and ask “what if?” Of course smaller organizations will have an easier time addressing unknown individuals while larger ones will struggle with adequate controls. However, it’s all about the simple controls – “Who are you? Who are you here to see? I’ll call to make sure they’re in. This person will escort you to them.” Funny, that reminds me of my introduction to Kerberos.

Friday, October 19, 2007

Interesting physical security government resources

Most of us deal with network and information security on a daily basis. At times, it can be both edifying and also daunting to read about what those on the front lines of physical security deal with.

Two of my favorites are the FBI list of concealed and hidden weapons, and the the DEA's Microgram Bulletin which lists concealed drugs - an interesting read for security analysts. Cocaine in hammock supports, other drugs in trailer hitches, and more.

If you've found an interesting resource like these, drop a link in the comments!

Wednesday, August 29, 2007

Email bomb threats

The Indiana Daily Student is carrying an article about an email bomb threat to Indiana University's Bryan Hall. The University of Iowa received a similar threat and noted that other universities are receiving these threats as well. With widespread email bomb threats spreading, it is useful to note that the email was sent with specific details - to a dean and threatening Bryan Hall in the case of IU, and threatening the library at UI. In addition, the article notes that the email was sent through an anonymous service. This is the modern day equivalent of phoning in your bomb threat from a payphone.

I've seen old style phone-in bomb threats can shut down classes and campus buildings for hours at a time. With the heightened security response from many schools in a post VA Tech mode, emailed bomb threats have a significant chance of disrupting school activities. As the school year starts, it will be interesting to see if this is just the beginning of a trend. Hopefully this won't become widespread - targeted availability attacks like this can wreak havoc on campus schedules and events.

Now is the time to review your emergency communications plan - can you communicate effectively to your staff, students, and other community members? Do you have evacuation plans for buildings?

Thursday, August 9, 2007

Google's new Case The Joint program

Google's Streetview provides a useful service - it shows you pictures of where you're going. Despite privacy questions, there is definitely a benefit to knowing what the building you're looking for looks like.

Now Google is introducing a program called the Google Local Business Referral program. You can become a representative and...

As a Google Business Referral Representative, you'll visit local businesses to collect information (such as hours of operation, types of payment accepted, etc.) for Google Maps, and tell them about Google Maps and Google AdWords. You'll also take a few digital photos of the business that will appear on the Google Maps listing along with the business information.
(Emphasis mine)

If you've ever done physical security evaluations, you know that having a good excuse to get in and take pictures is very handy. Well, here's a great opportunity - and you can get paid for it afterwards.

Is that a bit paranoid? Possibly. Will we see a rash of people noting that you can case the premises using Google's data? Also possible. The important thing is - does it increase risk? Yes - for some businesses such as banks and other high security locations that don't want the general public to be able to check where their security cameras are by doing a Google search. Those same risks exist with a camera phone carrying public, but those require physically visiting the location.

Just be careful when someone knocks on your door and mentions that they're with Google Houseview...

Friday, June 22, 2007

Physical Security - the unlikely does happen

Police in Tulsa are chasing a ring of criminals who are conducting large scale thefts that most security folks would rate low on the probability scale.

Their most recent heist involved rappelling from the ceiling of a Best Buy to steal a large safe and electronics. They even disabled the alarm system. In other thefts, they've stolen a semi-trailer sized load of electronics, and cut through the side of a building.

I've seen drywall walls cut through to get into an otherwise well secured room, and I've seen datacenters that had no security camera, easy dock access, and a back door latch easily tripped with a credit card or screwdriver. While we're not used to physical theft, it is a fact of life, and if you have valuable, portable items - or even not so portable items, there is a risk.

If you have valuable merchandise, or if your data center has business critical data, you might want to talk to your management about the unlikely, but possible...