Within our first day or two of arriving at Notre Dame, all of us got our student ID card. This required being photographed, and then getting the card with the strip on the back. This card served as our key to get into dorms, our meal ticket, and a virtual debit card on campus with FlexPoints and Domer Dollars being deducted from them. Periodically cards get worn down and the strip on the back no longer works much to the annoyance of the dining hall ladies who then have to punch in student ID numbers after several failed swipes. Sometimes, people lose them and have to get another one. Overall though, this card is with us almost continually for four years. There are plenty of security questions to consider when thinking about our ID cards though.
For all the access that the card provides, it really has very little security. In many ways, this is a good thing as no one wants to be hassled with producing multiple forms of ID or signing something every time they go to the dining hall or do laundry. There is a picture on the ID, but that picture is taken freshman year, and most people change in appearance plenty over their four years. Plenty of times the cashier doesn't even look at the picture to begin with, and in the case of Domer Dollars used on vending machines or laundry machines, there is no check at all. If a card is lost or stolen, anyone can use that card until it is reported and canceled. As a key, after parietals or when entering some side doors, only dorm residents can enter, and they require a swipe of the card and then punching in a four digit code, the student's birthday by month and day. However, if someone really wanted to get into a dorm, it would be easy enough to find out a birthday. Also, as I figured out due to my card getting really worn down and falling apart, the strip part of the card actually peels away from the front of the card with the name and photo. If someone really wanted to, they could switch card identities or make a false front and attach the back to it.
If I were an attacker trying to exploit these cards for my own use, the thing to do would be to quickly buy things with Domer Dollars or FlexPoints once I stole or found one. The attacker could spend some of it without ever having anyone even see the ID at vending machines and that type of thing. In another situation, if the person even looked vaguely similar, cashiers rarely look at the picture, and if they did, the person could just say that the picture was taken four years ago when they were a freshman. It would be difficult to buy a lot of things of large value, but it would be very easy to steal small amounts of money this way. Also, if a non-student wanted to get into dorms and had a card, this would be extremely easy for them to do with a stolen or found card. They could use this as a way to steal from dorm rooms. Once the owner realizes the card is gone, they will likely go get a new one, at which point the stolen or found card will no longer work. However, in the meantime, someone could spend quite a bit of money, and I don't think the student would get refunded if it was discovered.
It would be very difficult to make the ID card a lot more secure unless students were greatly inconvenienced. If the card system was changed, dorms would be difficult to get into, lines would move slower in the dining hall and the Huddle, along with many other things. A few things that could help would be to issue a new ID with a new picture every year so that pictures were more up-to-date. At the same time, there could be an increase in awareness on the part of the dining hall workers and cashiers to actually look at the picture. If there was a big difference, they could ask for a second form of ID. Part of the problem now is that most people seem to be too trusting.
Another suggestion might be to allow students to pick their own pin instead of making it automatically be the birthday as this could be easily found out. This might be expensive, but there could be a way to require a pin number before Domer Dollars can be used for laundry or for buying anything else. There is currently a way online to track use of Domer Dollars and Flex Points. Perhaps this should be better publicized so students can check usage on a more regular basis and see if anything looks suspicious.
To a large degree, there just has to be some risk acceptance though in order to keep the convenience of students in mind. The good thing is that the only personal information contained on the card is the student ID number, so stealing a card would not enable the thief to find out too much. Also as often as students use their IDs, they would likely quickly notice if their card was missing. They might look for it for a while in an attempt to avoid paying the replacement fee, but within a fairly short amount of time, they would have to get a new card, which would make the old card invalid. Thus, the risks are not such that too much increased security would make sense.
Showing posts with label Security Review. Show all posts
Showing posts with label Security Review. Show all posts
Wednesday, November 11, 2009
Sunday, October 4, 2009
Computerized Time Clocks
Computerized time clocks are a common technology in the workplace. I use a computerized time clock at both my job at home and my job here at the University. Before acquiring my current job at home, I worked at a small store that used a traditional time clock that required that each employee have a card for each week so that our boss could collect and record our hours at the end of the week. Computerized time clocks make this process of logging employee hours more efficient. With computerized time clocks, managers of organizations can simply use software programs to keep track of the hours that employees work and can distribute pay accordingly. For my job at home, each employee has a personal identification number, and when we arrive at work, we input this number onto the computer, and at that time we also select which role we will perform, i.e.: maintenance, wait staff, hostess, etc. For my job at the University, my coworkers and I use our student identification cards to “swipe in” to a magnetic card reader.
The owners of this technology expect that the computerized time clocks will protect the integrity and availability of the information that is stored on them. They expect that the identity of the employee, the number of hours that each employee works, and the task that the employee performs is authentic, and they also expect that the employees are consistently able to interact with the system. These expectations are part of the overall expectation that the time clock will be consistent, easy to use, and accurate. Also, as an employee interacting with the system, I would expect that my information would be kept confidential.
An attacker could want to exploit this system in several ways. The most frequent attacker of a system like this would be an employee attempting to make more money than he or she earned for the tasks that he or she performed or the number of hours worked. Other attackers could include competitors who want to shut down operations by either violating the integrity of the information, shutting the system down so that employees could not clock in, or disclosing personal information of employees like bank account numbers, assuming that the time clock software connects to the bank for direct deposit.
The biggest risk inherent to this system is that it is not monitored as thoroughly as traditional time clocks and is more vulnerable to employee dishonesty or tampering as a result. Like I said, at my job at home it is the employee’s responsibility to enter into the computer which task he or she performs that shift. Breaching the integrity of this system is as easy as telling the computer that I worked a higher paying job than I actually did every so often. Also for this organization, the employee identification number is only four numeric digits long, so it would be very easy for other employees or outside attackers to access my personal information.
As a manager who would use this technology I would mitigate my risks by putting several safeguards in place. To reduce my risk I would either make my employees’ identification numbers longer, or I would require them to enter two forms of identification to clock in. I would also make sure that my employee’s information was protected to insure that their bank account numbers were not vulnerable to theft. Finally, I would check the information stored by the computerized time clock at regular intervals to protect myself against expensive employee dishonesty.
The owners of this technology expect that the computerized time clocks will protect the integrity and availability of the information that is stored on them. They expect that the identity of the employee, the number of hours that each employee works, and the task that the employee performs is authentic, and they also expect that the employees are consistently able to interact with the system. These expectations are part of the overall expectation that the time clock will be consistent, easy to use, and accurate. Also, as an employee interacting with the system, I would expect that my information would be kept confidential.
An attacker could want to exploit this system in several ways. The most frequent attacker of a system like this would be an employee attempting to make more money than he or she earned for the tasks that he or she performed or the number of hours worked. Other attackers could include competitors who want to shut down operations by either violating the integrity of the information, shutting the system down so that employees could not clock in, or disclosing personal information of employees like bank account numbers, assuming that the time clock software connects to the bank for direct deposit.
The biggest risk inherent to this system is that it is not monitored as thoroughly as traditional time clocks and is more vulnerable to employee dishonesty or tampering as a result. Like I said, at my job at home it is the employee’s responsibility to enter into the computer which task he or she performs that shift. Breaching the integrity of this system is as easy as telling the computer that I worked a higher paying job than I actually did every so often. Also for this organization, the employee identification number is only four numeric digits long, so it would be very easy for other employees or outside attackers to access my personal information.
As a manager who would use this technology I would mitigate my risks by putting several safeguards in place. To reduce my risk I would either make my employees’ identification numbers longer, or I would require them to enter two forms of identification to clock in. I would also make sure that my employee’s information was protected to insure that their bank account numbers were not vulnerable to theft. Finally, I would check the information stored by the computerized time clock at regular intervals to protect myself against expensive employee dishonesty.
Labels:
Security Review
Subscribe to:
Posts (Atom)