Security Breach Case Study: A Literal Key to NY City

Author: Brian Rhodes, Published on Oct 04, 2012

How much would it take to bring a city to it's knees? How about $150? It sounds impossible, but that is exactly what has happened in NYC. A major security vulnerability has been exposed with a simple set of keys - a "fireman's key ring" - illegally sold to a newspaper. In this note, we peek into the security firestorm, the backstory, the costs involved to recover from improperly managed 'master' keys, and discuss how to prevent similar events in the future.

The Story

** * ********** ************** ** ******* ************, * ******* ********* (*********) ******* ** **** * *** of ****** **** ********* ******* ** **** ** ** ****** auction. **** ********** *** ** **** ** **** ********, *** to *** ******* ** '***********' **** ** ******* *** ******** common ** *** *********** **** *** ********* ****:

  • ******** ******* ******* ***:**** ******* *** ******** ** **** ** ** ******** ** the ****** ***** *** '****** ***' ** ******* ** ******* during * **** *****. **** ******** ******** ********* **** ******** trapped ****** ****, ** *********** ******* *** **** *** * car **** **** ****** ** **********.
  • ****** **** ****** ***:******* ******* *** **** ** ******* ****** ** ********** ***** of ***'* ****** ******, *** *** ** ****** **** ****** these *****.
  • ******* ******* *******/******: ***** ******** ********** ******* ***** * ****** *** *** quick ****** ** ******* ****** ************ *******.
  • ************ **** *********:******* ** '*********', ******* **** ** *** **** ********** ****** *** *********** holding *** **** *** ****** ************ ******** (* ***** ***** Center *** *****.)

*** *** ****** ** **** ********** *** **** ***** **** in *** '**** ******' ** **** **** ******** ** ***'* **** ********** ***** can ** ******* ******* ************* ** ******* ********** - ****************** **********, *******, ************.

***** ** ******* **** *** **** ***** ** *** *****, selling **** ******** ** * *****, *** *** ****** ****** has **** ***** *** ****** - **** *** ******* *** the *********** ***** ** ** ******** ***********.

The ****

**** ************ ********* ***** *** **** ** **** ***** ** tens ** *********, *********** ** ** ******** ** ********* ** dollars.

******** **** * ****** '****** ***' ***** **** **** ********* locks ********** *** ****, ****** * **** ** * **** can ****** ****** **** ********** *****. ******** **** *** ******* cost ** ********* * ****** **** ** $**-$**, **** *** effort ** ******** **** *** ***** ***** ***** ******* $**,*** - $**,***. **** ******** **** *** ******** *** ********** **** of ********* ****, ********** (** **** *****, ****) *********, *** the ******* ********** ***** ******** ** ********** *** ******* *** work.

Solving *** *******

***** *** ****** ** ******** *** ****** ******** ** *** story, *** ******* ******* ** ****** *** *******. ** ** previously ********* ** *** "*** *** ********** *** *******?" ******, **** **** ********** ****** ** ******** ********** ** also *** ** *** **** ********.

***** ** ********** ** * *** ********** ****** ** ***** by *** ******* *******, ******* ** *** *** ******* **** been **** ** ********** ********* ** **********. ********** ** *** details ** *** ********** ****** ** *****, *** ************ ***** a ********* ** **** ** *** * *** ** ****** keys ****** ***** *** ** ******** ** ***** *** ********** was ** *****.

***** ******** ******** ******, **** * ******** *** (********** * 'master' ***) ** **** ** ****** ** *********** ********, ** at ***** ********** ** ** ******* ****** ******* ********* ******. At *** ***** * *** ** *******, ********** *** ********** action *** ** ***** ** ******* *** *** ** *****/****** affected *****, ****** **** * *************** '****-****' ******** ****** ** fear.

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Related Reports

Access Control Commissioning / Install Checklist on Aug 03, 2017
This 80+ point checklist helps end users, integrators and consultants verify that access control installation is complete. It covers the following...
Smartphone Controlled Kevo Lock Tested on May 04, 2017
Smartlocks are a growing market, with millions sold. Kwikset's Kevo is one of the most common choices, using the Unikey smart phone access control...
Dell EMC Surveillance Division Profile on Apr 20, 2017
With revenue growth from traditional IT customers slowing, Dell has set a focus on the security industry as a market where the company can offer...
2Gig Intrusion Megatest (GC2 & GC3 Panels Tested) on Mar 28, 2017
2Gig is one of the most widely used intrusion systems, with two product lines that are the main offering of many alarm companies, huge national...
Lock Keyways For Access Control Guide on Mar 23, 2017
Lock keyways can be the difference between a lock working or not. Understanding keyways is important for access control. Indeed, a member recently...
Unikey Smart Phone Access Control Platform Profile on Mar 21, 2017
More and more people carry smart phones. Many think this could replace the conventional key or card for access control. However, using a phone...
Glass Doors and Access Control Tutorial on Feb 22, 2017
The biggest challenge for many access control systems are glass doors. Here's what happens when a maglock is improperly installed to an existing...
Integrator's Top Selling Cameras 2017 on Feb 13, 2017
8 manufacturers accounted for 80% of the top selling camera lines for ~150 integrator responses. This report demonstrates which brands integrators...
Arecont Lowest Favorability Results on Jan 25, 2017
Given Arecont is 3 time defending integrator choice for worst camera manufacturer, it should be little surprise they had the lowest score in the...
Axis TCO Study Examined on Oct 31, 2016
Axis is doing a full marketing push for a new TCO study, with various Axis divisions and their media partners promoting this TCO study. This...

Most Recent Industry Reports

Final Day Save $50 - IP Networking Course September 2017 on Aug 17, 2017
Today, Thursday, August 17th is the last day to save $50 on the September IP Networking Course. This is the only networking course designed...
Knightscope Raises $10 Million With $3,320 Average Per Investor on Aug 17, 2017
Congrats to Knightscope. And condolences to their legion of little investors. Knightscope has disclosed they have raised $10+ million from their...
Axis and Arecont Legal Conflict Over Multi-Imager Cameras on Aug 17, 2017
Arecont threatened Axis. Axis has responded by moving to invalidate an Arecont patent. It is an important contest. Multi-imagers are Arecont's...
Directory Of Consumer Security Cameras on Aug 16, 2017
The consumer camera segment continues to grow, with new startups and models from existing players released seemingly every month. In this report we...
Cat 5e vs Cat 6 vs Cat 6a Network Cable Usage Statistics on Aug 16, 2017
Cat 5e? Cat 6? Cat 6a? What do integrators use in practice, today? 140+ integrators told IPVM. Here are the results: For those who want to...
Hikvision Responds To Cracked Security Codes on Aug 15, 2017
Hikvision has responded to IPVM's report on Hikvision's security code being cracked, both with a 2 page update to dealers and communication...
Stolen Video NVR / DVR Statistics on Aug 15, 2017
"But what happens if someone steals my recorder?" Anyone who has done more than a handful of jobs has probably heard this question several times....
Hikvision Europe Cutting Out Unauthorized End User Sales on Aug 15, 2017
The days of anyone buying Hikvision from anywhere off the Internet are numbered, at least in Europe, if Hikvision's plan comes to fruition. In...
Axis Laser Focus PTZ Tested on Aug 14, 2017
Axis has been touting its new Q6155-E laser focus PTZ as 'always in focus' and 'always in color'. Does it really deliver? We bought and tested...
Vulnerability Directory For Access Control Cards on Aug 14, 2017
Knowing which access credentials are insecure can be unclear, especially because most look and feel the same. Even the most insecure 125 kHz types...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact