Key Duplication Issues

The police probably shouldn't have their keys hanging visible to the world.

I found this today online (thanks Bruce!). This story is about a guy who managed to duplicate the key used by Dutch police for their handcuffs.

The first main point to learn from this is that you have to be really careful when you walk around in public with identity badges or keys visible. They can be photographed at great distance and be duplicated at leisure (as in the example a while back where a researcher photographed a key on the ground from over 200 feet away and was able to make a working duplicate of it).

Second, he used a 3D printer to create the key from plastic instead of metal which was cheaper, easier and something most anyone can do (if they have or can get access to a 3D printer). It's worse because the key is plastic and won't trip a metal detector. But the issue that no one has talked about yet is the danger of the photo used to show off the key.

Here is the key, but something else important as well.

The person holding it (which I assume was the creator of the key) has fully visible fingers with ridge detail clear enough to possibly create a false fingerprint (just like he did with the key). In other words, by posting a photo showing his fingerprints, he may have just made the same mistake that the police did when they left their keys in the open to be photographed and copied.

Remember to always be careful when posting photos online.

Tags: , ,

Beware Blu-Ray Surprises

(Image is in the Public Domain)

Simply put, media should be media, programs should be programs. Putting code or commands into media like movies, music, e-mail etc allows for viruses or worse and no one should have to worry about that. Well, worry.

If you put the new Blu-ray Iron Man movie into your computer it will try to connect to the Internet and download something (some horrible DRM program probably?).

Tags: , , ,

Sarah Palin’s Private E-mail Account Hacked

(Image is in the Public Domain)

Sarah Palin's Yahoo account has been broken into and e-mails found there posted to Wikileaks. I would say this was a pretty rotten thing to do, but the perpetrators claim they did it to prove that Palin has been using her private e-mail to circumvent recordkeeping laws about government business. If that's true, then perhaps this needed to happen.

Tags: , , , ,

Insult to Injury: Countrywide Data Breach Affects Millions

(Image is in the Public Domain)

It isn't bad enough that Countrywide was engaging in questionable loan practices , but now they've lost the data on millions of customers as well.

And, as usual, the completely worthless response:

The company nevertheless promised to provide two years of free credit monitoring to affected individuals through the ConsumerInfo.com division of the Experian credit bureau.

*Sigh*

Tags: ,

The World’s First “Unclonable” RFID Chip – Yeah Right

(Image used under: Creative Commons 2.0 [SRC])

The website includes very loose information about what makes this chip so "uncloneable", but I highly doubt that it's true. An RFID chip is read by radio waves and as long as you can make a chip, computer, or anything else that transmits replicate the signal that the original chip did, you can clone it.

If they mean that you can't make one of these chips copy the data from another of these chips, I can see that as being possible, but what difference does that make in the end if I can use a different brand chip to open your secure door or travel the world in your name?

Tags:

Stealing Cellphone Data Takes Only Seconds

Digital Pickpocketing
(Image used under: Creative Commons 2.0 [SRC])

There's a small device that when plugged into many cellphone brands (and the list is growing) that can copy all data on the phone. In other words, if someone wanted to know every bit of data you have on your phone, they could ask to "borrow it for second", plug this thing in when you weren't looking and hand it back.

While designed for law enforcement, this device is available to the public for only ~$200

The rule: if your phone contains sensitive data, do not leave it unattended. If you loan it to someone to use because they tell you theirs is not working, make sure you actually see them using the phone and there is nothing connected to it.
Tags:

How to Fly If You’re On the “No Fly List”

(Image is in the Public Domain)

Bruce Schneier explains how easy it is to get past security and fly on a plane even if you're on the supposed "no fly list"

Buy a ticket in some innocent person's name. At home, before your flight, check in online and print out your boarding pass. Then, save that web page as a PDF and use Adobe Acrobat to change the name on the boarding pass to your own. Print it again. At the airport, use the fake boarding pass and your valid ID to get through security. At the gate, use the real boarding pass in the fake name to board your flight.

His article on why the no-fly-list and photo ID checks are useless against terrorists here.

Tags: , ,

California Wireless Toll System Hacked

Bad security is worse than none in some case
(Image used under: Creative Commons 2.0 [SRC])

This is hardly surprising. The wireless toll systems use RFID and there isn't an RFID system yet that hasn't been hacked that I know of. Anyway, by cloning anyone's transponder, you can pass through the tolls while the other sucker pays the bill. Also useful for committing crimes in someone else's name.

Tags: , ,

Best Western Loses Full Details of All Customers From 2008 in Data Breach

Data breaches are about negligence; every time
(Image is in the Public Domain)
Details of how to access the information - which included home addresses, place of employment and credit card details - were sold through an underground network operated by the Russian mafia.

And, again, if these companies would stop holding our credit card numbers far past the date that we used them, we wouldn't be having this problem.

Update

Best Western is contradicting the story saying that it's exaggerated. More importantly this:
Most importantly, whereas the reporter asserted the recent compromise of data for past guests from as far back as 2007, Best Western purges all online reservations promptly upon guest departure.

If this is true, then how did they lose anything? Did they? The details are unclear.

Tags: , ,

States Throw Out Worthless Diebold Voting Machines

(Image is in the Public Domain)

It's actually very encouraging that the same states that were originally duped into buying these machines despite the vast mountain of evidence of their general worthlessness have become smart enough to remove them in time for the upcoming election.

And about this:

"I have a huge inventory of machines that I am not able to use," she complained. "They are just sitting in our warehouse basically useless." Stacked to floor to ceiling are 4,000 machines purchased at $3,500 each. Total cost of that system: $16 million.

How exactly does Diebold get away with selling defective merchandise to the government without being forced to issue a refund?

Update

Today Ars Technica also covers the story and adds some interesting details. For example, it turns out that in one case a voting machine company offered to buy back their machines from the state for $1 each (their original price was $5000 each). At least the state was smart enough to decline). Tags: ,

Loading...

If you want to learn more about my professional background, click here to learn more.

Check out one of my guides/tutorials:

seminar destroy Tutorial
|INDEX|next: The Consequences of Posting Online
Online Addiction: From gambling to surfing and online gaming, people can destroy themselves and others with online addiction.
Posting Online: The Internet never forgets anything completely. Make sure you don't make mistakes that will stick with you for the rest of your life.
Protecting Photos: The Internet never forgets anything completely. Make sure you don't make mistakes that will stick with you for the rest of your life.
Getting Tricked: You WERE doing fine... until someone convinced you to install a virus or give away your passwords. Don't fall for it!
Account Hijacking: One of the most common security risks today is people getting their accounts taken over and then used to trick their friends and family.
Trusting Webservices: An online service promises they'll 'Never abuse or misuse your data' and you believe them? Think again.

... or check out any of my other guides and tutorials by clicking here!

Online Addiction

Concerned about online addiction? You should be. Learn the types, the signs, and the preventions.

[Click for full description]

The Consequences of Posting Online

It's fun to post online. What you think, what you feel. But words typed and posted on the Internet can come back to bite you more than anything you could say with your mouth.

[Click for full description]

Photo Safety

You can reveal far more than you intended when you post a photo online. Don't make a critical mistake and check your photos before they're online.

[Click for full description]

Tricks and Scams

Just because you won't willing give up data doesn't mean that I can't trick you out of it. Don't fall for these well known tricks!

[Click for full description]

Account Hijacking

One of the newest threats we face is the risk of someone getting control of your online account and using it against you and the people you know. Do everything you can to prevent that from happening!

[Click for full description]

Trusting Companies

Store, online or off, are not known for being fair and helpful unless it benefits them to be so. Good deals exist, but many are bad deals in disguise. It's not in your best interests to be too trusting with any of them.

[Click for full description]