Bruce Schneier | |||||||||
Schneier on SecurityA blog covering security and security technology. « Bad Quote | Main | Wi-Fi Shielding Paint » December 29, 2004Canadian Airport Security Loses UniformsFrom CBC News: 1,127 uniform items belonging to Canadian airport screeners were lost or stolen in a nine-month period. I'm not sure if this is an interesting story or not. We know that a uniform isn't necessarily a reliable authentication tool, yet we use them anyway. Losing 1,127 uniforms is bad, because they can be used to impersonate officials. But even if the 1,127 uniforms are found, they can be faked. Can you tell the difference between a legitimate uniform and a decent fake? I can't. The real story is the informal nature of most of our real-world authentication systems, and how they can be exploited. I wrote about this in Beyond Fear (page 199): Many authentication systems are even more informal. When someone knocks on your door wearing an electric company uniform, you assume she’s there to read the meter. Similarly with deliverymen, service workers, and parking lot attendants. When I return my rental car, I don’t think twice about giving the keys to someone wearing the correct color uniform. And how often do people inspect a police officer’s badge? The potential for intimidation makes this security system even less effective. Posted on December 29, 2004 at 08:37 AM • 17 Comments • View Blog Reactions To receive these entries once a month by e-mail, sign up for the Crypto-Gram Newsletter. I'm not disagreeing, but 1127 uniform "items" doesn't strike me as being the same as 1127 uniforms. An item could be as simple as a belt or a pair of socks. Posted by: Mike at December 29, 2004 09:03 AM I had once encountered a search situation involving Federal Agents, who being with warrant had threatened to break down the door. When we asked to see their ID, they said they would show us after we let them in. Being that it was early in the morning, that we had just woken up to the sound of the pounding on the front door, and that we did not want our front door knocked down, we did not know what to do. So we let them in. It could have been anybody. Even when we looked at the ID we realized we had no way of knowing their authenticity. After the fact, I have thought about that incident many times and I really wish that there was a phone number we could have called to verify the warrant, etc., because no ordinary citizen could really have known the authenticity of the warrant (do you know your local/state/federal judges by name?). A phone number, like 911, which is publicly known and even taught to children at schools would probably be a good public service tool to prevent someone from impersonating an official and robbing you blind. Posted by: C.S. Lewis at December 29, 2004 09:53 AM Reminds me of a scene I saw in Ft. Lauderdale airport a year ago. I was waiting for a friend's arrival. There is a corridor where recent arrivals exit from. There are no doors or gates of any kind. Just a sign on the top saying "Exit only" and a couple of employees sitting on stools on either side of the wide corridor to check that nobody comes in. While I'm waiting I see this policeman in uniform, with a gun mind you, coming in through there and just waving hello to the attendants. Was he a policeman? Or just somebody in a stolen uniform? This happenned well after 9/11. Apparently we still have a lot to learn. Posted by: Alex Feldstein at December 29, 2004 09:54 AM Just a thought... Most 'uniforms' (aside from police army etc) are sold by commerical stores who will sell them to anyone (least in NY where I live) Its the badges they need to fake.. (sort of) but its fairly easy to gate in behind someone with a bit of tact. Posted by: LarryConley at December 29, 2004 10:08 AM Human beings are quite fallible and are the weakest elements of security. Even if these uniforms weren't stolen or won't be used for any illicit purposes, there would still be many of ways to get people and objects through security. Uniforms of any kind would make this a lot easier. Someone could probably tailgate into luggage or maintenance areas and easily change back into a "passenger" disguise, or anything else. They could probably enter offices without much trouble. For that matter, it wouldn't have to be in Canada, either. A "Canadian airport screener" would probably have an easier time dealing with any security in any area at any airport. Having a lot of stolen uniforms would also work well for organized groups. Posted by: Francois Kashy at December 29, 2004 11:01 AM Purchasing Police and Army Uniforms isn't THAT hard. I'm currently wearing a 5.11 Tactical shirt. It's essentially a police shirt. It has handy "concealed" pockets, it came with epaulettes and instructions to attach them. It even came with a badge holder tab (for those police forces that use that kind of badge I guess)... I'm not a police officer, I just saw a review of the shirt, found a local stockist and bought one. The stockist also supplies some but not all of the local police forces. They sell a variety of Police badges and the like. They said that you need to show official ID in order to buy those, but the majority of police type items that they sold didn't require such rigourous checks. If I want a police baton, or body armour then I know where to buy it now. They also sell handcuffs, handcuff keys and so on. As for Army uniforms, it seems that the local thrift stores usually have some form of Army uniforms in them. I don't know enough to know which particular uniforms these are, but they are definitely military uniforms. No ID checks no nothing. The local Army surplus stores also seem to sell both parts of Army uniforms and badges. Z. Posted by: Zwack at December 29, 2004 12:37 PM You don't even need a uniform, a boiler suite some technical language and a clipboard will get you in most places. As long as you don't try the front entrance. Just look like you are suposed to be there and people will ignore you. Posted by: Jeb at December 29, 2004 06:20 PM What you might be touching on here is an anthropological view of appearances and culture. There are at least two variations on reasons I often hear for uniformed clothing: Posted by: Davi Ottenheimer at December 29, 2004 06:49 PM Last year sometime I looked out the window to see a guy walking around in my yard. Being a suspicious person, I grabbed the closest thing to me (the chair I was sitting on) and went for a closer look. Posted by: Graham at December 29, 2004 10:01 PM Just buy a blank badge and get someone else to inscribe some official looking text on it. At a store here that supplies police as well as the security community, you can buy nice looking ones with the Oklahoma state seal on them, no questions asked.
Posted by: Kirby at December 29, 2004 10:04 PM Like Jeb said above, coveralls / jeans and a plaid shirt, a tool belt, a small stepladder, and a clipboard will get you into a surprising number of places. Many people will let someone into places like the wiring closet and then ask the building management later if at all. Posted by: cynthb at December 30, 2004 05:12 PM "I'm not disagreeing, but 1127 uniform "items" doesn't strike me as being the same as 1127 uniforms. An item could be as simple as a belt or a pair of socks." Good point. I missed that. Posted by: Bruce Schneier at January 2, 2005 04:50 PM For one glaring example of how far the right language and behaviour can get a talented imposter, check the case of the German Gert Postel: http://www.gert-postel.de/english.htm Although a mailman without any medical training, Postel managed to pose as a senior psychiatrist in a Saxon hospital for more than two years. Posted by: Bratgitarre at January 4, 2005 08:04 PM Vaguely related: there are companies which offer secure uniform destruction. Of course it isn't all that hard to tear up a shirt on your own premises but woven cloth badges are fairly tough, and also harder to fake.
Posted by: Roger at January 16, 2005 09:21 PM Just think about how well this will work! Terrorists will only stay with terrorists and write all that information down. Non-terrorists will stay with non-terrorists. Soon you'll have two XOR'd sets, can take action, and then reduce the size of government by closing DHS. Posted by: joe at January 20, 2005 04:40 PM Sorry to follow-up myself, but I just remembered seeing a fancy sewing machine which will accept an appropriately formatted data file, then sit there and embroider pretty well anything. It could use fine metal wire as well as thread. The lady who owned it said that such machines are pretty common nowdays (a really top line one is about four thousand US, but many are cheaper), and enthusiasts exchange pattern files over the net. This conjures an amusing image: gangsters trafficking in (security) embroidery patterns! Maybe seamstresses will have their file collections raided, looking for forbidden stitches 8^) Posted by: Roger at January 20, 2005 11:55 PM Another good example of uniform fraud: 76 years ago a couple of guys walked into a garage wearing Chicago police uniforms. The 7 men inside did not react adversely to seeing these two officers. It turned out they were setting up a job for two plain-clothed associates, with the result being the St. Valentine's Day Massacre. Posted by: Ted at January 25, 2005 03:23 PM Post a comment
Powered by Movable Type 3.2. Photo at top by Steve Woit.
Schneier.com is a personal website. Opinions expressed are not necessarily those of BT Counterpane. |
|
Comments