4 ms·
Yeah, until a man gains easy access to 17-year-old girls' housing, then everyone will flip out. I mean, it's one thing to break stuff to get in, or conspicuousl
by slirpee 11y ago
Yeah, until a man gains easy access to 17-year-old girls' housing, then everyone will flip out. I mean, it's one thing to break stuff to get in, or conspicuously pick a lock, it's another to casually slide a card like everyone else and leave no trail other than maybe video surveillance or access logs showing the same card being used at two ends of campus faster than possible (which nobody will check until something bad happens and they go looking at that data.)
I had a similar experience at my university. I found easy unauthenticated sourcing of most of the data needed to clone the card of anybody by name. The issue number was the only thing to guess, but easy to bruteforce on something low-stakes like vending machines. The card was used for food, a debit-card-like system, automated door locks to semi-public buildings and on-campus housing.
With the permission and cooperation of the university security, I made a card of a high-level security guy (who could have been targeted using the public/semi-public org chart) and swiped into their datacenter where all the university data is hosted, along with that of some partners with sensitive data. Luckily the innermost parts need an RFID or something which I didn't have access to, but potentially I could have tailgated or social-engineered my way into that. They weren't interested in letting me research whether I could crack the RFID. :(
I was told my demo made a big splash, but IIRC I checked a year or two later and my source for the ID data was still wide open. There's having imperfect locks and then there's leaving all your keys out in public.
- sliverstorm 11y agoit's another to casually slide a card like everyone else How about to casually insert a duplicated key like everyone else?
- slirpee 11y agoIt's true, I didn't consider this enough. But I had a way to create a key without ever possessing the original. If it could only be copied from the original, as even a semi-competent implementation of a magstripe would be, there would still be the chance that someone notices a theft of a key, and it's just harder to pull off if you have to find and covertly steal a key. My point is that being able to trivially hijack arbitrary identities without even knowing the person let alone physically finding them, is not "good enough." It'd be like if you could make arbitrary car keys with just a VIN, and the VIN is displayed prominently, it would be silly to say "Well now, it keeps honest people honest, so it's good enough."