linux operating commands and unix operating commands

The Insecure Air Freshener

 
Thread Tools Search this Thread
# 1  
Old 03-31-2009
The Insecure Air Freshener

At a recent trip to an office building, in the restroom there was, up in the corner, a battery-powered  air freshener that automatically sprays potpourri scent every half hour. It is a white box about the size of 2 stacked VHS tapes (remember those?) mounted up in the corner against crimson tile.  And it had, to my amazement, a brass lock to keep the lid securely closed.

The lock was a simple, inexpensive brass lock anyone can buy at Home Depot for a few bucks, screwed into the plastic side with standard gold-colored  screws. So, I was wondering...why was it locked? I don't know the history, nor do I deal with air fresheners often. I myself cannot think of a good reason for doing this. So I wanted to do some deconstruction of the impetus behind what I find to be a somewhat irrational act.

To set the stage, this bathroom is not located in a secure facility. It is a nondescript typical corporate office building in the suburbs. Therefore, the logic used for locking the device, as far as I can see, falls into one of two categories (or both):
  • Security: so no one can steal the air freshener can or batteries
  • Public safety: so no one can install a can of aerosol anthrax
And the lock down was probably facilitated by either:
  • An overzealous organizational security policy
  • An overzealous security officer
  • An overzealous custodial engineer
But again, perhaps this is a wise practice, to lock down air fresheners in corporate restrooms, and it's me who is being naive. I would hate to be the one who has to answer why I didn't lock down the air freshener after such an attack (or theft) occurred. If I do start to see this more, I may chalk it up to a weak economy, where people steal air freshener parts similarly to how thieves steal copper pipe and wire from homes in economically-depressed areas. But for now, I tend to see this as an irrational act of security, the result of watching too much local news and crime dramas.

Also, some concerns:
  • If someone who steals air freshener components is being allowed into the building, why and how?  What else is at risk?
  • The lock is cheap and easily compromised
  • Has equal attention been made to other possible vectors of whatever attack the lock was intended to prevent?
I guess the point is, if you're going to implement a security measure, make sure it is in response to a definitive requirement, that it is effective, and that you don't let it eclipse other threats and vulnerabilities that also need to be mitigated.

Image
Image

More...
Login or Register to Ask a Question

Previous Thread | Next Thread

3 More Discussions You Might Find Interesting

1. AIX

How to disable insecure protocols?

Hello all, planning to secure AIX sever by disabling insecure protocols/cipher suites; got the below requirements from secuirty team. 1.configure the server to disable support for DES and IDEA cipher suites 2.disable insecure TLS/SSL protocol support Configure the server to... (4 Replies)
Discussion started by: Kumar7997
4 Replies

2. Cybersecurity

PCI DSS Compliance : Insecure Communication Has Been Detected

From the nessus scanner tool report i got below vulnerability PCI DSS Compliance : Insecure Communication Has Been Detected http://www.tenable.com/plugins/index.php?view=single&id=56208 As per the description given in above link - I am not able to understand How to find insecure port... (2 Replies)
Discussion started by: saurabh84g
2 Replies

3. UNIX for Advanced & Expert Users

More command insecure

The more command allows a user to invoke shell. If it is run using the sudo command this will give a user a possibility to run whatever he wants with root's privilegies. Does anybody know about a command with the same abilities that more but without escape to shell? (2 Replies)
Discussion started by: odashe
2 Replies
Login or Register to Ask a Question