Bruce Schneier | |||||||||
Schneier on SecurityA blog covering security and security technology. « Security-Breach Notification Laws | Main | Defeating the Shoe Scanning Machine at Heathrow Airport » December 13, 2007Bank Vault Plans Found in TrashA Berlin hairdresser discovered top-secret plans for a safety vault at the Bundesbank's Berlin branch in a bin, the German central bank said Thursday. Posted on December 13, 2007 at 12:32 PM • 28 Comments • View Blog Reactions To receive these entries once a month by e-mail, sign up for the Crypto-Gram Newsletter. It would be interesting to see these documents. But they are probably not being disclosed. Posted by: Thomas Damgaard at December 13, 2007 1:00 PM In America they would charge her with a crime for finding those plans. "Unauthorized possession of intellectual property with intent to embarrass" or some such nonsense. (Or running with scissors.) Posted by: Alan at December 13, 2007 1:21 PM Or they would put card locks on public recycle bins ;> Posted by: Anonymous at December 13, 2007 1:38 PM At the rate at which German banks are beginning to go under, it may be a mute issue to have plans of the vault available to the public. Posted by: For Real at December 13, 2007 1:50 PM BTW, "Bundesbank" is not just another German Bank ... it is _the_ Federal Bank ... Posted by: Anderer Gregor at December 13, 2007 2:06 PM > A Bundesbank spokeswoman ... said Famous last words. Posted by: White Star Cruise Lines at December 13, 2007 2:16 PM I guess that Bundesbank has yet to even discover a shredder? Posted by: Fred P at December 13, 2007 2:19 PM Being not an expert at breaking into vaults, is this not akin to revealing the code for an electronic security system? I.e. if well-designed, its not a big deal? P.S. In college I found (still have, somewhere) complete blueprints for a reasonably nearby supermax prison expansion. I presume that if the FBI ever busts down the door, that will be added to my crimes. Posted by: shoobe01 at December 13, 2007 2:33 PM @Alan Yes, America arrests you for stupid things. Unlike other countries like England that will just arrest you for walking down a bike path. Posted by: m at December 13, 2007 3:00 PM shoobe01, I guess I'm kind of like you. If I found secret plans I'd hang onto them until I figured out something useful to do with them. This kid never should have reported the blueprints. But he did, the authorities confiscated them, and now Bundesbank will probably learn the plans. I don't know if this "found in the dumpster" story is going to hold up under waterboarding. He may be headed to a prison near you. Maybe you should dig out those old blueprints and lend the guy a hand. Posted by: Tangerine Blue at December 13, 2007 3:02 PM @Thomas Damgaard Not to worry, the concerned citizen brought the plans straight to Germany's flashiest tabloid - Bild - which promptly ran them on its front page http://www.bild.t-online.de/BTO/news/2007/12/07/bundesbank/sicherheits-skandal,geo=3191962.html Has a 'photo galllery', in which you can get at least a bit of an idea of the type of document. Posted by: dragonfrog at December 13, 2007 3:25 PM "What, these? I... uh... I found them in the trash! That's right! The trash!" Posted by: Pat Cahalan at December 13, 2007 3:31 PM @m That story is fantastic - arrested as a terrorist for walking on a public bicycle path. I quite liked this quote: 'Ms Cameron said: “It is utterly ridiculous that such an inoffensive person as myself should be subject to such heavy-handed treatment.â€? ' She's got them sussed, even if she doesn't realize it - where they slipped up was in treating a wealthy white lady poorly. If they'd just stuck to scary brown-skinned people, it would all have been fine. Posted by: dragonfrog at December 13, 2007 4:38 PM I think rummaging around in a trash can is a much more serious offence than taking photographs from a train! Posted by: Anton at December 13, 2007 4:47 PM @m Perhaps when mainstream people (and real estate developers) realize what stupid controls our governments are "introducing" on us, more people will laugh in the face of authority. Then again, maybe we're all neutered sheep. Posted by: Constable Jones at December 13, 2007 5:10 PM I wonder if this was some sort of Cold War-style dead drop that was intercepted? Posted by: Wil at December 13, 2007 5:15 PM @dragonfrog Thanks. I hope someone will release hi-res scannings of the plans on the web. The images in the "gallery" is not worth much. Posted by: Thomas Damgaard at December 13, 2007 6:18 PM Bundesbank is probably just trying to prove that security by obscurity is unnecessary. Posted by: Roger Moore at December 13, 2007 8:51 PM That is what you call the weakest link of the chain. Also, weak links are there in all chains... Posted by: Niyaz PK at December 13, 2007 10:12 PM (from the article posted by "m") "because of September 11, I would be arrested and charged." What was she going to do? Run into a building (repeatedly) to bring it down? This really is sad. I can't think of a better word for it. Next thing you know, having your car parked longer than you have paid for will be classified as "terrorism". This should have been, at most, a traffic offense, and I'd be laughing if she would have gotten a ticket for that. It's something like running a red light with your bicycle in the Netherlands. Of course that is an offense, but just about everyone does it, and people very rarely get more than a verbal warning and have to promise they'll never do it again. How can someone who is walking be a security risk, when a cyclist isn't? What if she was riding her bike there, and she had to walk because she got a flat tire? Would that be a threat as well? Posted by: Sparky at December 14, 2007 1:30 AM Anybody remember Ray Bradbury's "The Pedestrian"? From the 50s sometime. Anybody have a record of an earlier incident of detention for the crime of walking than this?-- Summer of 1962, LA suburb with no sidewalks because nobody would walk there, guy walking, picked up as suspicious character. Of course, I don't have the clipping any more. Posted by: Porlock Junior at December 14, 2007 3:52 AM Aren't vaults like crypto algorithms. There security is based on the secrecy of *only* the combination/key. The plans should not change anything.... Posted by: greg at December 14, 2007 7:03 AM Reminds me of the time I was in junior high and I wanted to make a Doom level modeled after my school (sounded like a cool idea at the time). Note this was before any of these senseless public school shootings began to take place. I told the school that I wanted to make a 3D model of the school on my computer at home. Not only did they give me blueprints to the school to take home, but they gave me their only copy of the blueprints. I traced it at home and promptly returned it the next day (wanted to minimize the potential of it getting lost). Never got around to making that level (probably for the better). Looking back on it given the recent school shootings that have taken place, I wouldn't dare ask something like that even if I had the best of intentions. But it still baffles me that they just gave me the blueprints (I was expecting some sort of security protocol to go through). I guess they too wouldn't dare do something like that nowadays either. Interesting how times change. Posted by: Anonymous Coward at December 14, 2007 4:14 PM @At the rate at which German banks are beginning to go under, it may be a mute issue to have plans of the vault available to the public. Maybe those weren't plans. Those were real-estate prospectuses (prospecti?) re: doom levels for schools. If I was the local SWAT, that's precisely what I'd want --- accurate doom levels for my SWAT to *practice* with. It's all a question of making sure that you pick the right "bad guys"
Posted by: Michael Richardson at December 15, 2007 6:34 PM In my area of the U.S., it's illegal to go 'dumpster-diving'. If you're seen rummaging through trash bins of any business or privately own garbage bin other than your own, you will be jailed and charged for criminal trespass. Posted by: rdeckard at December 18, 2007 7:41 AM Didn't see this one, but the big "secret" in many bank vaults is that the door side is the only strong part, which works out as most crooks are dumb and try to go in the same way as the employees do. Near here, recently, a small bank branch was robbed by a couple of guys with a pickup truck who simply rammed the outside brick wall and thus broke down the "back wall" of the safe. Of course, they were soon caught, many things in that safe had recorded serial numbers, and no point having what you can't use. Posted by: DougC at December 20, 2007 11:10 AM "...they were plans that would lead the Rebel forces to the main reactor." Posted by: summer at January 31, 2008 4:28 PM Post a comment
Powered by Movable Type 3.36. Photo at top by Steve Woit.
Schneier.com is a personal website. Opinions expressed are not necessarily those of BT. |
|
Comments