 Stiv2kRm -Rf As Root join:2002-07-22 Orlando, FL | Barcodes and security gates - WTF?! The apartment complex I am currently living in has been having a problem with escalating crime (robbery, car theft, blah blah), so they recently invested some $700,000 into a new security gate system at all the entrances, plus an overabundance of security cameras.
Okay, all that stuff sure sounds pretty neat, but here's the catch. To allow residents in through the gates, each resident will be provided with a barcode sticker (still not sure at this time whether or not each resident has a UNIQUE barcode or if they just give out the same code to everyone). That's right, BARCODE STICKER. No RFID tags, magnetic strips, nothing. Just picked this baby up today and here's what she looks like (attached).
So, does anyone else here notice the GARGANTUOUS security hole that this system creates? What is stopping me from using barcode software to create a replica of a valid decal and using it to gain unauthorized entry into the neighborhood? Or scanning my decal and printing out copies of it? This all seems like it'd be way too obvious of an exploit to overlook, someone fill me in on this!
Furthermore, I found it quite humorous that they are charging $200 to replace your decal if you lose it or break it. HAHA.
PS. After the system goes active (ETA about 2 weeks) I am going to try to exploit it myself, I will be sure to post results.
Thanks -- - Steve Bularca
irc.neoturbine.net - NeoturbineNET IRC |
|
 statestress magnetPremium,Mod join:2002-02-08 Purgatory kudos:6 Host: Webhosting Android Sonic.net UK Broadband FAQ Owners chat
| If nothing else, it's a deterrent to keep people from crusing through the complex I suppose...If someone really wanted in, they'd just hop a fence somewhere. Interesting though, never seen barcode decals being used to gain access to a gated community. Most places I've been in the past either use a code at the gate or a magnetic card. |
|
 RobIn Deo speramus, God Bless the USAPremium join:2001-08-25 Kendall, FL kudos:2 | reply to Stiv2k Reminds me of a funny story..
About 2 years ago a buddy and I went over this lady's house to fix her computer. She lived in a gated community. So we pulled up to the visitor lane, and didn't know her phone #, so we couldn't call her to open the gate. So as we sat there wondering what to do, another car pulls up next to us in front of the gate, and the passenger hops out walks over to the gate, leans down and waves his hand over the sensor. Viola, the gate opens up.
So after the car went in, my buddy did the same thing, and in we went with the car. -- www.rr.cx - My Blog YourIP.US - It's Your IP .. and more! MySite.cx - Free URL Redirection Service. |
|
 ropeguruPremium join:2001-01-25 Grafton, WV | reply to Stiv2k Can tell you that it probably will not keep unauthorized people out very long. The least bit tech savvy person will just reproduce the bar code and give it away to whomever they want to.
Hell, they may even be able to just photo copy that bar code and use the copy to get in. Cannot imagine what other "security" could be built into that sticker. |
|
 Juke BoxI Know His Word Never FailsPremium join:2001-01-29 John 3:16 Reviews:
·Comcast
·AT&T Southeast
| reply to Stiv2k I live in a apartment complex similar to that. Well, it is just a gated community requiring a RF device to open the gate when you drive in.
Actually, I like it that way. Though, where I live is the more expensive neighborhood, Mt. Pleasant SC.
You should be thankful they are doing something to more secure the area. -- If you are having half as much fun as I am, then I must be having twice the fun than you are. Do The Math! |
|
 TechnogeezAgape in amazement.Premium join:2007-01-20 | reply to Stiv2k You realize, of course, that by posting the pic in your rant, you've enabled anyone to D/L and print a copy on reflective tape... -- Read your contract and TOS before signing anything. |
|
 Phantom 2On no he can'tPremium join:2002-05-13 | You guys kill me.This company spends big money to keep the residents safe and then you whine about it and try to beat the system.The property owners should be commended for their pro-active approach to resident safety. -- Welcome home Vietnam Vets."We were soldiers once...and young" |
|
 dvd536as Mr. Pink as they comePremium join:2001-04-27 Phoenix, AZ kudos:4 | reply to Stiv2k Just like locks, will only keep the 'honest thieves' out |
|
 MaxoYour tax dollars at work.Premium,VIP join:2002-11-04 Tallahassee, FL | reply to Stiv2k Just move. Gated communities suck. I much prefer regular neighborhoods. Just my opinion though.  |
|
 Stiv2kRm -Rf As Root join:2002-07-22 Orlando, FL | reply to Technogeez said by Technogeez:You realize, of course, that by posting the pic in your rant, you've enabled anyone to D/L and print a copy on reflective tape... That is quite my intention, perhaps the creators of this security system *should* have had that in mind when they designed it.
By the way, I've been trying to identify the barcode symbology used on the sticker, but so far I have not had much luck. Is it possible that they use some sort of proprietary/private symbology that nobody else knows? The reason I say this is because if I can reproduce the barcode without even having a picture of the original (just the number), then I am going to consider bringing this up with the management.
If anyone has any information regarding which symbology that is, please let me know |
|
 MaxoYour tax dollars at work.Premium,VIP join:2002-11-04 Tallahassee, FL | I can verify with you that this barcode is not using the usual format. All standard barcodes (to the best of my knowledge) have two thin lines that at the end, middle, and beginning of the code. It works like this ||Manufacturer ID||Product ID|| The thin lines separate the manufacturer ID, which is unique to each manufacturer, from the product ID, which is unique for each product to each manufacturer. The barcode you present does not follow this standard. -- "Padre, nobody said war was fun now bowl!" - Sherman T Potter
»www.cafepress.com/maxolasersquad
»maxolasersquad.com/
»maxolasersquad.com/network/ My DSL Network Guide
»myspace.com/mlsquad |
|
 Stiv2kRm -Rf As Root join:2002-07-22 Orlando, FL | Is it still possible to decode it? Pattern recognition of some sort? |
|
 MaxoYour tax dollars at work.Premium,VIP join:2002-11-04 Tallahassee, FL | I recon so, but there isn't really anything to decode. each of those lines, depending on size and position, represents a number. If you where to decode the number the computer uses, it would be a useless/useful as the original barcode. You could assign each bar it's own number and come up with your own numbering pattern to make additional barcodes, but they wouldn't get you in unless they also matched up with the number of another resident. -- "Padre, nobody said war was fun now bowl!" - Sherman T Potter
»www.cafepress.com/maxolasersquad
»maxolasersquad.com/
»maxolasersquad.com/network/ My DSL Network Guide
»myspace.com/mlsquad |
|
 Stiv2kRm -Rf As Root join:2002-07-22 Orlando, FL | Perhaps this may be breaching the point of "going too far" but curiosity killed the cat as they say. I'm going get my room mates to give me their stickers and see if i can recognize any sort of pattern, god knows what will happen  -- - Steve Bularca
irc.neoturbine.net - NeoturbineNET IRC |
|
 UncleScooterBubbles, I like BubblesPremium join:2002-04-15 Tallahassee, FL | Whatever you do, DO NOT overlap the barcodes, EVIL things will happen!!!!!!!!!!  |
|
 MaxoYour tax dollars at work.Premium,VIP join:2002-11-04 Tallahassee, FL | reply to Stiv2k You probably won't notice any pattern. If you could see them the way the computer sees them it would just be a bunch of random numbers, like 18372958002. Another person might have 78392047615. These numbers probably represent each individual renter so it knows who is coming and going and when. Having numbers on the side of your car would make it very difficult for the scanner to read. That's the purpose of bar codes. The computer can quickly read them and convert them to numbers internally. The fact your landlord knows every time you enter your community is reason enough for me to not want to live in a place like that. -- "Padre, nobody said war was fun now bowl!" - Sherman T Potter
»www.cafepress.com/maxolasersquad
»maxolasersquad.com/
»maxolasersquad.com/network/ My DSL Network Guide
»myspace.com/mlsquad |
|
 Juke BoxI Know His Word Never FailsPremium join:2001-01-29 John 3:16 Reviews:
·Comcast
·AT&T Southeast
| said by Maxo:The fact your landlord knows every time you enter your community is reason enough for me to not want to live in a place like that. I was ok with everything you said so far until you mentioned the above.
How does this differ from a community watch program, aside from the obvious surveillance equipment used at the apartments?
Are you afraid they may come to you when you drive in and ask for the rent? Not trying to be sarcastic here but I really don't see the point. -- If you are having half as much fun as I am, then I must be having twice the fun than you are. Do The Math! |
|
 MaxoYour tax dollars at work.Premium,VIP join:2002-11-04 Tallahassee, FL | I enjoy being the holder of my personal information. There's nothing special about which pair of underware I'm wearing today, and there's not really much one can do with that information, but I'm not for having that information freely available to people. I enjoy my personal privacy and the ability to relese it on my own terms. |
|
 Juke BoxI Know His Word Never FailsPremium join:2001-01-29 John 3:16 Reviews:
·Comcast
·AT&T Southeast
| What, in regards to coming and going?
This is an apartment complex and the landlord doesn't want people that don't belong there at the location. Or look at this way, having the bar code gives you a right of passage to the complex. I really don't see how that intrudes on your privacy.
It is no different if you lived in a residential neighborhood. Your neighbors will always notice your car entering and leaving your driveway. If it is you, no big deal. If it is someone suspicious, there would be a cause of some kind of concern but you have been watched.
Personally, I would thank the apartment complex for trying to make their customers/guest as safe as possible trying to reduce crime there. -- If you are having half as much fun as I am, then I must be having twice the fun than you are. Do The Math! |
|
 MaxoYour tax dollars at work.Premium,VIP join:2002-11-04 Tallahassee, FL | I'm not really interested in arguing for my views on privacy in this thread. The OP is free to disagree or agree with my original statement. I don't really care. |
|