When I first got access to the Internet, my parents were quite paranoid about me talking about when we'd be going on vacation, and when people weren't home. I'm not sure if they're still paranoid about it, but I admit I think about their concerns every time I mention that I'm in another city on Twitter.
However, I've never seen anyone get that point across so nicely as pleaserobme.com which uses Foursquare and Twitter to build a nice list of people who aren't home right now. Combine that with a little extra observation to find out where their homes are, and I bet you'll probably also find a wealth of other information about the things they own that are worth stealing. Handy for all your thieving needs!
I wonder how many people will rethink using Foursquare after seeing this. I'm guessing not actually that many, though. Just like Facebook, a few people will be appalled, but more will be thinking "eh, that'll never happen to me." My supervisor asserts that people will only really care about privacy when someone from Google goes completely bonkers and uses the information at their disposal to kill someone. But I am not sure even that would be enough: they're already risking people's safety with gaffes in new products, and while that gets people upset, I know I haven't closed my Google accounts or turned off the phone that's transmitting my location data to them all the time...
Mind you, I know how easy it is to break in to my house and I haven't upgraded my locks either, just bought insurance and backed up my digital assets off-site. I know how insecure my credit card is, yet I'm counting on the law to keep me from being liable if it's abused. And you can buy insurance on top of that for identity theft.
So sure, I'm happy to hear that the Canadian privacy commission wants to know more about Google Buzz. But what I'm really wondering is how to sell insurance for privacy. I'd make a killing in this market!
(Addendum: If only I could figure out how to make that work... Can't you just imagine a team of lawyers descending upon your mother to do damage control when your friends' drunken antics get leaked through Facebook?)
Showing posts with label physical security. Show all posts
Showing posts with label physical security. Show all posts
Wednesday, February 17, 2010
Thursday, November 27, 2008
Physical key security (highlights from ACM CCS)
I recently attended the security conference ACM CCS, and I wanted to share some of the talks I really enjoyed at the conference. Many of these are a little outside the scope of web security, but I think you'll find them interesting too!
Today's post is about the paper Reconsidering Physical Key Secrecy: Teleduplication via Optical Decoding by Benjamin Laxton, Kai Wang and Stefan Savage at the University of California, San Diego. This one was almost out of scope even for the conference (which is Computer and Communications Security) because it focused on physical security, and the computer was only involved as a tool to break it.
Mechanical locks and keys are a staple of physical security. A basic key is a piece of metal with notches along one side. When pushed into a lock, the key moves a set of tumblers inside the lock so that the whole thing can be turned, allowing the door (or whatever) to be opened. The thing to note about keys, in this case, is that for a given key manufacturer, those notches only have a set number of possible depths, and there are only a set number of notches. The whole key can be represented as a string of numbers showing the notches.
So what they did, is they built a system that could take a picture of a key and produce that string of numbers. Once you have that string, you can enter it into a key-cutting machine, and voila, you have a copy of that key. (In fact, some keys they showed actually had this number written on the key for easy duplication in case it was lost!)
The thing that was perhaps a little disturbing is how easily they could do this. They could duplicate a key from all sorts of photos, with keys at all sorts of angles. They showed a lot of online photos of people's keys and mentioned the popular "what's in your bag?" meme. Their web searches found many keys that their system could decode and duplicate... often people even gave the address that went with the keys!
Then they got into stuff that really seemed to come out of a spy movie. With a bird spotting scope and a digital camera, they started taking pictures of keys that were further and further away... at 35 feet they could duplicate the key every time. At 65 feet, it took two guesses before they could get all keys. At 100 feet, still only three guesses were necessary. And then they climbed onto the roof of one of the university buildings and took a picture of a set of keys 195 feet away on a table below, and still managed to decode one of them correctly. James Bond apparently could use some modern academic research!
The take-home message here? If you want to keep things physically secure, you'd better make sure no one sees the keys! For more information, check out the complete paper.
Today's post is about the paper Reconsidering Physical Key Secrecy: Teleduplication via Optical Decoding by Benjamin Laxton, Kai Wang and Stefan Savage at the University of California, San Diego. This one was almost out of scope even for the conference (which is Computer and Communications Security) because it focused on physical security, and the computer was only involved as a tool to break it.
Mechanical locks and keys are a staple of physical security. A basic key is a piece of metal with notches along one side. When pushed into a lock, the key moves a set of tumblers inside the lock so that the whole thing can be turned, allowing the door (or whatever) to be opened. The thing to note about keys, in this case, is that for a given key manufacturer, those notches only have a set number of possible depths, and there are only a set number of notches. The whole key can be represented as a string of numbers showing the notches.
So what they did, is they built a system that could take a picture of a key and produce that string of numbers. Once you have that string, you can enter it into a key-cutting machine, and voila, you have a copy of that key. (In fact, some keys they showed actually had this number written on the key for easy duplication in case it was lost!)
The thing that was perhaps a little disturbing is how easily they could do this. They could duplicate a key from all sorts of photos, with keys at all sorts of angles. They showed a lot of online photos of people's keys and mentioned the popular "what's in your bag?" meme. Their web searches found many keys that their system could decode and duplicate... often people even gave the address that went with the keys!
Then they got into stuff that really seemed to come out of a spy movie. With a bird spotting scope and a digital camera, they started taking pictures of keys that were further and further away... at 35 feet they could duplicate the key every time. At 65 feet, it took two guesses before they could get all keys. At 100 feet, still only three guesses were necessary. And then they climbed onto the roof of one of the university buildings and took a picture of a set of keys 195 feet away on a table below, and still managed to decode one of them correctly. James Bond apparently could use some modern academic research!
The take-home message here? If you want to keep things physically secure, you'd better make sure no one sees the keys! For more information, check out the complete paper.
Labels:
academia,
CCS,
physical security
Subscribe to:
Posts (Atom)