Showing posts with label physical security. Show all posts
Showing posts with label physical security. Show all posts

Thursday, November 23, 2023

AFK: Parking Enforcement

Working as a University of Texas parking enforcement officer since 11 September has allowed me easy access to the libraries that I use most often, even though I have not been able to pry away time to visit more. (I did see the Gutenberg Bible at the Harry Ransom Center.) The morning drive to work takes one hour (40-50 minutes) and the commute home can take two (45 to 90 minutes). I am working tomorrow’s football game against Texas Tech from 6:30 AM to 7:30 PM. (The pay is great: with game day overtime and event bonus, it comes to the same as being a technical writer.) 

Some Saturdays have been devoted to the City of Kyle Public Library Astronomy Club and others to the Austin Astronomical Society and I still edit (and sometimes write) a monthly column for the Historical Astronomy Division of the AAS (here: https://had.aas.org/resources/astro-history). Something had to give. 

I try to find whatever personal rewards that I can for self-actualization and transcendence (from Maslow’s Hierarchy). Meanwhile, I now watch the clock and looked forward to Friday. The advantages include semester-long checkouts at the libraries, healthcare insurance, as much walking as I choose to do (and I love walking), along with the light physical challenges of wrestling 22 lbs. of iron around an SUV’s tires to immobilize a scofflaw.  

I also have the opportunity engage in
philosophical discussions about semantics.

 

At the snack bar here,
the food is not labeled correctly
and they do not give out receipts for purchases.

 

This is still my favorite.

 Waiting to be written are these researches.



Like the problem of the tree that falls in a forest when no one is around, the fact is that there is sound in space. Stellar events create shock waves that cause compressions and rarefactions in the particles that comprise what we too easily call empty space.

NGC 6231 is easy to see in the lower body of the Scorpion. It has not been easy for professionals to sort out which stars are bound in the open cluster, which are background and which are foreground. I sketched it several times.


IC 1296 is a barred spiral galaxy that often appears in amateur photographs of the more famous M57 Ring Nebula in Lyra. In fact, I believe that it is an easy claim that amateurs have produced more photographs than professionals. I ran a literature search on the Harvard NASA database of articles and found some references. 


Messier 30 appeared here in October. I would like to recast those as a single magazine article. The cluster is moving opposite to the inertial frame of the Milky Way. So, professional astronomers believe that it was captured in a collision with another galaxy.


PREVIOUSLY ON NECESSARY FACTS

AFK: Away from the Keyboard

AFK: Hurricane Harvey

Minimizing the Likelihood of Bad Cops

Junk Criminology as Pseudo-Science


Saturday, May 20, 2017

TDEM 2017 Texas Emergency Management Conference

Laurel and I attended the 2017 Texas Department of Public Safety Division of Emergency Management annual conference in San Antonio. Although it is a four-day show, we were there just for Thursday, May 18. We started with the exhibit hall and attended two break-out sessions. These are some of the vendors whom I met.

Dr. Deb Zoran is the operations supervisor of
VET outreach of Texas A&M University.
They coordinate animal rescue during disasters and emergencies.
John Taylor and Hannah Coffey of BOLD Planning,
one of the providers of mitigation and remediation plans for
organizations that do not have adequate in-house emergency planning.
Sean Scott developed the Red Guide handbooks.
They are available in English and Spanish.
Keith Blaylock of eXpress Sandbag System
did not bring the proprietary machinery with him.
However, I found the sandbags to be portable,
standardized, and stackable.
And he said that he could produce
1000 per hour all day long.
Michael Shanks of LRad explained
that his sound output speakers will cover
huge, city-sized areas with good clarity
for voice notification in times of emergency.
Mike Ross does apps and he has them for
emergency management. In the age of the
smartphone it is an easy and effective way
for jurisdictions to get the word out --
the right information...
from the right source.
Vanessa Forté of ProPac brought a wide range of
pre-packaged emergency supplies from
first aid kits to food and drink for
one person or large groups.
Mark Mathiesen of On the Mark Weather is one of several
commercial meteorologists with his own brand of applied theories.
When I reviewed and edited contracts for TDEM in 2014,
I was surprised to learn that the government agency, NOAA,
as respected as it is, is not the leading edge, and only tells you
what they tell everyone in a wide area all at the same time.
Dr. Mathiesen specializes in micro-events:
he can tell you if your school could be hit. 
Of course, there were many more to be met.  My friends from Intermedix and WebEOC were there. So were the folks from STEAR, the State of Texas Emergency Assistance Registry for people who want to be helped when getting help is a matter of life and death. I met Major Ernest Branscum of the Salvation Army several times during the day as we toured the exhibit hall. I was happy to be able to add my name to the contact list for the local chapter of the Association of Continuity Managers.   

On Thursday, May 18, at 4:00 PM, Laurel and I attended an excellent session on Insurance Fraud. The presenters were Lt. David Taylor (Compliance) and John Plent (Consumer Protection) from the Catastrophe Response Team of the Insurance Fraud unit of the Texas Department of Insurance. Just to note: The Department of Insurance is one of about 20 state agencies and departments that has its own sworn and weaponized peace officers. As explained below, when on the streets, talking to roofing contractors, he has the full law enforcement authority of any police officer in Texas.

In the aftermath of a disaster, swarms of unlicensed contractors appear, soliciting business, and being paid with money from insurance settlements. The work is uneven in quality. Sometimes, the “contractors” take a “down payment” and never return. Occasionally, they take a partial payment, do partial work, then leave, with a promise to return, which puts the matter out of the criminal law and into civil law.

The TDI catastrophe teams help people work with insurance adjusters; and they can assist insurance companies in the field. They work with consumers to help with insurance claims. Lt. Taylor and Mr. Plent come to your town to mitigate (and ideally prevent) violations and victimizations. They start by meeting with city officials. They acknowledge that after a severe storm which has taken lives, mitigating insurance fraud might not seem highly important. However, they have found law enforcement and other city officials to be very helpful. If the city has regulations, they say, then make sure that all solicitors are registered and licensed. Drive the streets; and where you see roofers working or knocking on doors, ask to see their papers. Municipalities should run background checks for outstanding warrants and sex offender registration. Their primary advice is to homeowners is to never accept a solicitation. You, the customer, should drive the process by seeking out reputable companies and getting competitive bids.

We have no state-level licensing of contractors here in Texas. However, we do have the Roofing Contractors Association of Texas and the Building Officials Association of Texas (BOAT at www.boatx.org). In fact, BOAT was one of the vendors at the TDEM conference. 


Read about the fraud team here
Watch one of their videos here.

At 2:30 PM on May 18, Laurel and I attended a disjointed, lackluster session on cyber security.  Despite our abiding professional involvement in computer security, this one put us both to sleep. The presenter was David Morgan (CISSP, CNSS NSA Security), who is a cybersecurity officer and information security manager at the Texas Department of Public Safety. He certainly seemed well qualified from his time in the Marine Corps to his experience as a visiting professor at several colleges and universities. The bottom line is that the content of his presentation did not meet the criteria set by the title of his talk, "Cyber Security - A Critical Component for Emergency Management." 

Everything we do in response to a disaster or a community event depends on computers, from smartphones to laptops. To coordinate our efforts, we bring WebEOC into community shelters. Some at this conference had special responsibilities for the emergency bands such as TICP (Texas Interoperability Communication Package) and MARS (Military Affiliate Radio System). David Morgan did not tell us how to secure any of them, or how to detect an intrusion.

Laurel and I were most interested in knowing about how computer hackers have disrupted emergency response. Aside from mentioning the recent incident in Dallas -- (Dallas Morning News here among very many others) -- in which the weather sirens sounded at midnight, he had nothing to say. 

Hackers have been changing traffic lights since at least 2003, though the ability to do so was known in the 1980s. (See Wired from 2005 here.) Recently, the Surprise, Arizona, city 911 was taken out by a hacker (See Washington Times story here.)  Bear in mind, though, that the infamous “Operation Sundevil” from 1990, which alleged that hackers had broken into the nationwide 911, was exposed and disgraced.  (See  “Operation Sundevil” in Wikipedia here and “Jefferson in Mirrorshades” in a hacker archive here. )  None of that was in this  presentation. 

David Morgan did allude to the existence of viruses, worms, trojans, and spyware, but did not differentiate among them, or tell us how to detect, mitigate, remediate, or prevent them. He did say that the Macintosh operating system is easily given to viruses because it is based on Unix, which is the operating system in which viruses were invented. David Morgan defined “Zero day” as the source of unknown vulnerabilities. He explained a “root kit” by saying that if you are “root” then you own the system.

All of that being as it may, I personally benefited by learning about Shodan.io. Coming to work the next day, I visited the site, read about it on Wikipedia, and made a note to myself to follow up. 
  
PREVIOUSLY ON NECESSARY FACTS
BSides Austin 2016
InnoTech 2015
CERT: Community Emergency Response Team
The Living Fish Swims Under Water

Saturday, April 2, 2016

BSides Austin 2016

The seventh annual BSides Austin computer security conference ran March 31-April 1, 2016. I served as a Host for breakout sessions, introducing speakers, and keeping track of time. It was an overflow crowd of 350 with 150 turned away at the door, or denied a slot on the wait list. In addition, several student groups could not be accommodated at all. 
 
Breakfast with the Sponsors.
We had two tracks on Thursday and three on Friday. You can find the full schedule on the conference website here.  Many of the sessions were easy to label. “I am a Software Developer. What do you mean I’m on the Blue Team?” by Aaron Poffenberger was clearly for the Blue Team. “It’s not About the Technology. It is About the Psychology” by Dr. Hend Ezzeddine and Flora Moon was easy to label for Social Engineering.
 
32 Formal Technical Sessions
The first night also included open mike
"Fire Marshall Talks"
But many others crossed several lines on the corporate org chart, and the sessions were not narrowly defined. You had to pick your presentations. That said, all of the hands-on workshops were held in the same room on the same day.
 
Rapper "Dual Core"
Each track had a Host and a room Monitor.  The monitors counted the room three times (beginning, middle, end) and interfaced with the hotel staff when needed.
 
Waiting for the Keynote by Ed Skoudis from SANS.
The convention would have cost ten times as much to attend were it not for the sponsors. 
Digital Defense, Rapid 7, SANS, and Splunk were gold sponsors this year. 
The silver sponsors were RSA, Log-MD, ISSA, Pluralsight, Checkmarx,
Anomali, and Netskope.
The five core sponsors were Velocitystorm, Expressworks,
Fusion-X (thanks for the beer!),
No Starch Press, and Pentester Academy.
As a technical writer, my interests are more general. I am seldom held accountable for information security, except as we all are. These were among my take-aways:
  • The best lockpicking tools for the money are the Sparrow Tuxedo ($40) and the Tremendous Twelve by Toools from Southern Specialties ($30). 
  • The best locks are biaxials from Medeco and the Schlage Primus. You can spend $75 for one of these and secure your servers, or you can buy a dozen others at $5.95 each and let us all have access to your servers.
  • For a knowledge worker your credibility is your product. 
  • The highest priorities for information security should be Asset and Inventory Management, Decision and Remediation Workflows, and Visualization and Metrics. The lowest priorities are vulnerability assessment and scanning, penetration testing, and buying cool tools. 
  • Work the OWASP Top Ten vulnerabilities. 
  • Amateurs target systems. Professionals target people. 
  • Security will not be accepted until and unless IT is made personal: it is you in your home who will be violated by your release of company information at work.

Basic security
They call it “BSides” in honor of the old rock ‘n’ roll 45 rpm single releases of the 1950s and 60s. The producer picked a hit for Side A and put something else (usually mediocre) on Side B. Elvis Presley’s “Don’t Be Cruel” was an exception. The Beatles releases were all exceptions.
Presentations crossed organization lines
The concept began in the US in 2009 with Mike Dahn, Jack Daniel, and some others because the CFP [Capture the Flag: computer intrusion challenge – MEM] for Black Hat Vegas or DEF CON was oversubscribed and those unable to present decided to hold their own conference on the 'b side'. -- https://en.wikipedia.org/wiki/BSides

PREVIOUSLY ON NECESSARY FACTS


Monday, August 24, 2015

Bleeding Data: SXSW Interactive Proposal

With new data breaches appearing in the news every day, how can anyone protect their information? With a few simple tools - which we will demonstrate - you can dramatically improve the privacy of your personal information. 

Among the tools that we will provide and explain are Secunia PSI; KeePass Password Manager; and OpenDNS.

We chose those and other tools because they have high reputational value in the computer security community. They are easy to use. They specifically protect the most vulnerable aspects of your information flow. 

We will guide the workshop attendees through the installation and use of the tools. Tutors from the Austin computer security community will be on hand to provide individual instruction.

Selection of SXSW Interactive workshops and panels is, in part, by open voting. To vote and view the proposal video click here: http://panelpicker.sxsw.com/vote/50060

You can view the video directly on YouTube here:


You can read more about how to protect your personal information on Laurel's blog, IntentionalPrivacy.

Also on NecessaryFacts:

Saturday, October 18, 2014

Securing Your Viper Against Cylons

If you have a late model car, someone could take control of it while you are driving.  They could disable the brakes, command the steering wheel, set the speed, open the doors, disable the airbags, or explode them.

Computers in cars go back to the 1978 Cadillac Seville.  The chip was a Motorola 6800, used also in early personal computers.  It ran the car’s onboard display that provided eleven outputs such as fuel economy, estimated time of arrival, and engine speed.  By the turn of the Millennium, upscale BMWs and Mercedes boasted 100 processors. Even the low-tech Volvo had 50. (Automotive Mileposts website and Embedded website.)
Commander Adama would not allow
the computers on the battlestar Galactica to be networked.
His ship successfully resisted cyber attacks.

 From http://en.battlestarwiki.org/
The General Motors OnStar system was launched in 1995 and went from analog to completely digital in 2006.  (Wikipedia here.) 

Now, such radio systems are a standard feature on common makes and models. With that link someone can take control of your car.

The older your car, the safer you are.  A vehicle from the 1980s or 1990s will have electronic controls, but they will be less open to attack from the outside.

The Mark VII vipers were the newest and the best.
The Cylons destroyed them
by hacking their computers from the outside.

From http://en.battlestarwiki.org/ 
 
When the Cylons attacked, these museum relics were
pressed into action because they lacked computers
that could be jammed and compromised.
From http://en.battlestarwiki.org/
Two different security projects have been reported.  In both, “white hat hackers” investigated ways to take control of different models of automobile.

In 2011, Car and Driver told about the work of the Center for Automotive Embedded Systems Security, a collaboration between academics from the University of Washington and California State University at San Diego.  First, they plugged their own device under the dashboard to compromise the on-board diagnostic computer.  (Anyone who can get to your car could do that the next time you take it in for an oil change or other routine service.)  In the second phase, they figured out how to do that remotely.
Such breaches are possible because the dozens of independently operating computers on modern vehicles are all connected through an in-car communications network known as a controller-area-network bus, or CAN bus.
Even though vital systems such as the throttle, brakes, and steering are on a separate part of the network that’s not directly connected to less secure infotainment and diagnostic systems, the two networks are so entwined that an entire car can be hacked if any single component is breached.”“Hack to the Future”, Car and Driver, July 2011 by Keith Barry here.

In the words of the researchers:
 “We demonstrate that an attacker who is able to infiltrate virtually any Electronic Control Unit (ECU) can leverage this ability to completely circumvent a broad array of safety-critical systems. Over a range of experiments, both in the lab and in road tests, we demonstrate the ability to adversarially control a wide range of automotive functions and completely ignore driver input—including disabling the brakes, selectively braking individual wheels on demand, stopping the engine, and so on.”
 “Experimental Security Analysis of a Modern Automobile” by

 Karl Koscher, Alexei Czeskis, Franziska Roesner, Shwetak Patel, Tadayoshi Kohno, Stephen Checkoway, Damon McCoy, Brian Kantor, Danny Anderson, Hovav Shacham, Stefan Savage.
 IEEE Symposium on Security and Privacy, Oakland, CA, May 16–19, 2010. Available as a PDF from the authors here.
“Modern automobiles are pervasively computerized, and hence potentially vulnerable to attack. However, while previous research has shown that the internal networks within some modern cars are insecure, the associated threat model—requiring prior physical access—has justifiably been viewed as unrealistic. Thus, it remains an open question if automobiles can also be susceptible to remote compromise. Our work seeks to put this question to rest by systematically analyzing the external attack surface of a modern automobile. We discover that remote exploitation is feasible via a broad range of attack vectors (including mechanics tools, CD players, Bluetooth and cellular radio), and further, that wireless communications channels allow long distance vehicle control, location tracking, in-cabin audio exfiltration and theft. Finally, we discuss the structural characteristics of the automotive ecosystem that give rise to such problems and highlight the practical challenges in mitigating them.”
 “Comprehensive Experimental Analyses of Automotive Attack Surfaces” by Stephen Checkoway, Damon McCoy, Brian Kantor, Danny Anderson, Hovav Shacham, and Stefan Savage (University of California, San Diego) and Karl Koscher, Alexei Czeskis, Franziska Roesner, and Tadayoshi Kohno (University of Washington). Available as a PDF from the authors here.

Onboard diagnostics are integral to any sophisticated vehicle.
The computers on Galactica were not networked.
(From http://en.battlestarwiki.org/)
 Two years later, Andy Greenberg, who reports on technology for Forbes, filed a story about Charlie Miller and Chris Valasek who carried out their car hacking research with a government grant. 
“Miller, a 40-year-old security engineer at Twitter, and Valasek, the 31-year-old director of security intelligence at the Seattle consultancy IOActive, received an $80,000-plus grant last fall from the mad-scientist research arm of the Pentagon known as the Defense Advanced Research Projects Agency to root out security vulnerabilities in automobiles.”  Forbes, August 12, 2013 with embedded video here.

They took Greenberg for a ride that ended in a crash despite everything he could do to fight for control of the car. (The 5 mph roll out stopped in some high grass.)

ALSO ON NECESSARY FACTS

Monday, August 4, 2014

Firefighters

At the checkout of my local HEB Grocery Store, the guy behind me had a cake: "Good luck ...  Manchaca Fire Department..."  I handed him my card, and said that although I am a technical writer, my degrees are in criminology.  "You  don't get that with police," I said, indicating the cake.  "No?" he asked.  "I would not expect it," I replied.  We thanked each other and I left.  The police are necessary and important; without them, you have a failed State.  That being so, nonetheless, firefighters live the hardest line of the highest virtues in protection of the lives and properties of others.    

FEMA has a ton of statistics that necessarily hide the people. The Yarnell Hill Wildfire of 2013 took 19 City of Prescott firefighters. 

On June 18, 2007, nine firefighters died when the roof of a burning warehouse collapsed. One witness called it “a tornado of fire.” They entered the building to search for one person reportedly still trapped inside. Although this was the worst loss since 9/11, multiple fatalities are common in firefighting.  

At the same time, their continuous-duty cycles – living at the station for one to  three days at a time – means that they have other jobs, other careers, other concerns that take them away. That creates a challenge for the chief who needs to maintain levels of competency and efficiency. Furthermore, the rigorous, on-going education makes a trained firefighter valuable to any department; and that reinforces any desire to move away from a community to pursue those other careers.



"If his intuitions are unclear, he will call in a captain to meet the prospect, but,  generally, as long as the legal requirements are met, what counts most is impressing the chief as someone who is professional and community-oriented." “We have 32 people here with 32 personalities,” he said. His firefighters come from all of the diversity groups in his  community. “You take them as they are,” he said, “a perfectionist or a slob. You learn their personality and live with it and you get used to it. We rely on each other. Police are  trained to be loners. Firefighters are trained to be a team.”

[From A Taxonomy of Teamwork, term paper  for Business Management 386: Organizational Behavior and Theory, Dr. Richaurd Camp, Eastern Michigan University, Summer 2007.]


PREVIOUSLY ON NECESSARY FACTS

Monday, June 2, 2014

Longhorn Fire and Safety

We needed a new fire extinguisher, so I searched for "Austin fire extinguishers."  Reading the web pages showed that Longhorn Fire and Safety was probably the best bet.  They promised not to be undersold or out-serviced.  

On the way there, I stopped at Home Depot and took pictures of their array.  Longhorn met the Home Depot price on a Kidde and recharged our old First Alert.  


http://www.longhornfireandsafety.com/

Matt was fun to deal with. He is a honest horse trader.  The First Alert was the landlord's equipment. Like the others with which we have been provided by different owners and agents in different states over the years, it was charged when they gave it to us, but not tagged and sealed.  Now it is. 

ALSO ON NECESSARY FACTS
Volunteering in an Emergency: What to Expect
Around Austin
Locksporting
Shifting the Paradigm of Private Security
Employee Theft

Tuesday, June 18, 2013

Meanwhile ...

For the past three weeks, several projects took me away from blogging. "Documentation for Developers" was the topic when I addressed my Ruby on Rails group.  I spoke on the subject of private security to my local DefCon group.  Then, last week, I volunteered to present a chapter of exercises from Wireshark 101 to an OWASP lunchtime study cell.

Over the years, working on projects for different companies on different platforms for different audiences, I developed a set of guidelines for creating documentation.  The focus of this presentation was that developers can begin that process by relying on tools such as Microsoft Visio to design their systems.  Other tools include Nassi-Shneiderman charts and Warnier-Orr diagrams. "Do not design in code" is the only mandate.   Creating a software system and then calling in a technical writer is like building a house and then calling in a drafter to draw the plans. Documentation is specification.

I also drew on the allusion from Joseph Weizenbaum of the compulsive programmer as a compulsive gambler.  The code developer's superstition is that one more patch, one more fix will overcome a lack of knowledge of the substantive literature of the application field.
(The slides are on Slideshare here.)

For the hackers at DefCon 512, my goal was first to overcome the common myths about security guards.  We are subjected to ridicule.  Self-deprecating humor works for Big Bang
Theory because we have A Beautiful Mind, Sneakers, Johnny Mnemonic, and Hackers (with Angelina Jolie) to provide depth and drama.  Nothing like Law and Order: Special Victims Unit exists for private security.  That pro-police propaganda is contradicted by the absolute facts that more money, more resources, more personnel exist in private security, as much as three-to-one over public policing. Most people do not know that 36 private guards died when the Twin Towers came down.   I have worked with a Ph.D. philosopher, a nuclear engineer, two ministers, and an airline flight attendant.  Security guards are not the buffoons we are caricatured to be by mass media presentations in service to the central government.  Moreover, if you let us, we prevent problems because that is the nature of all businesses: business looks to the future; government attempts to remediate the past. My PowerPoint for this is on Slideshare here.


Wireshark is a tool for computer network security analysis.  Our study group is sponsored by OWASP, the Open Web Application Security Professionals.  They meet once a week at lunch for an hour to work out of some chosen book.  Our current project is Wireshark 101 by Laura Chappell.  I volunteered to work all of the labs in Chapter 3: Display Filters.    As a technical writer, I do this all the time, coming in to some technology, getting a handle on it, and presenting it to others.  

This is Chappell's smaller book on Wireshark.  The labs are direct, step-through exercises to show how the toolbars, menus, options, and selections all work.  I captured one or more screens for each lab, and made them into a PowerPoint presentation.

Previously on Necessary Facts
The Shifting Paradigm of Private Security
Private Security in the 21st Century
Locksporting
Redshirts: Expendable in Fiction and Fact