<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>ProSecurityNews &#187; LSI</title>
	<atom:link href="http://lsieducation.com/blog/category/lockmasters/feed/" rel="self" type="application/rss+xml" />
	<link>http://lsieducation.com/blog</link>
	<description>Security News and Commentary for Industry Professionals</description>
	<lastBuildDate>Sat, 09 May 2009 14:23:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<!-- podcast_generator="podPress/8.8" - maintenance_release="8.8.6.3" -->
	<copyright>Copyright &#xA9; 2012 ProSecurityNews </copyright>
	<managingEditor>prosecuritynews@gmail.com (Jon Payne, Sr., CML)</managingEditor>
	<webMaster>prosecuritynews@gmail.com (Jon Payne, Sr., CML)</webMaster>
	<category>posts</category>
	<ttl>1440</ttl>
	<image>
		<url>http://lsieducation.com/blog/images/psn_144x144.jpg</url>
		<title>ProSecurityNews &#187; LSI</title>
		<link>http://lsieducation.com/blog</link>
		<width>144</width>
		<height>144</height>
	</image>
	<itunes:subtitle></itunes:subtitle>
	<itunes:summary>Security News and Commentary for Industry Professionals - Locksmiths, Security Technicians, Military, and Federal and Local Law Enforcement.</itunes:summary>
	<itunes:keywords>locksmith, lockmasters, training, vault, security, homeland, law enforcement, military</itunes:keywords>
	<itunes:category text="Technology">
		<itunes:category text="Tech News" />
	</itunes:category>
	<itunes:category text="Education">
		<itunes:category text="Training" />
	</itunes:category>
	<itunes:category text="Business">
		<itunes:category text="Business News" />
	</itunes:category>
	<itunes:author>Jon Payne, Sr., CML</itunes:author>
	<itunes:owner>
		<itunes:name>Jon Payne, Sr., CML</itunes:name>
		<itunes:email>prosecuritynews@gmail.com</itunes:email>
	</itunes:owner>
	<itunes:block>yes</itunes:block>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://lsieducation.com/blog/images/psn_600x600.jpg" />
		<item>
		<title>PSN009 &#8211; Drive by passport cloning, ATM thefts, NFC Enabled Locks and more.</title>
		<link>http://lsieducation.com/blog/2009/02/psn009-drive-by-passport-cloning-atm-thefts-nfc-enabled-locks-and-more/</link>
		<comments>http://lsieducation.com/blog/2009/02/psn009-drive-by-passport-cloning-atm-thefts-nfc-enabled-locks-and-more/#comments</comments>
		<pubDate>Sat, 07 Feb 2009 22:05:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Electronics]]></category>
		<category><![CDATA[Hacks]]></category>
		<category><![CDATA[Locks]]></category>
		<category><![CDATA[LSI]]></category>
		<category><![CDATA[New Products]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://lsieducation.com/blog/?p=131</guid>
		<description><![CDATA[In this episode we discuss drive-by passport cloning, huge ATM thefts, NFC enabled electronic locks, a new biometric idea to replace fingerprint readers, 1500 Megapixel images for security surveillance, and yet another cool miniature spy cam. We also make note that Lockmasters Security Institute is now fully approved by the General Services Administration (GSA) as [...]]]></description>
			<content:encoded><![CDATA[<p style="margin-bottom: 0in; text-align: justify;">In this episode we discuss drive-by passport cloning, huge ATM thefts, NFC enabled electronic locks, a new biometric idea to replace fingerprint readers, 1500 Megapixel images for security surveillance, and yet another cool miniature spy cam. We also make note that Lockmasters Security Institute is now fully approved by the General Services Administration (GSA) as a Certified Training Facility for the GSA CERTIFIED Safe &amp; Vault Technician Courses. With over 400,000 GSA containers in use, can you afford not to become certified?</p>
<h2 class="western" style="text-align: justify;">Show Links</h2>
<p><a href="http://www.shmoocon.org/presentations-all.html#edl">Driveby passport cloning</a><br />
<a href="http://www.shmoocon.org/presentations-all.html#edl">Shmoocon DC – passport hack revealed</a><br />
<a href="http://www.google.com/patents?id=yd2iAAAAEBAJ&amp;dq=ASSA+or+Abloy&amp;as_psra=1&amp;ie=ISO-8859-1">RFID pressure switch patent</a><br />
<a href="http://www.idstronghold.com/content/secure-sleeve®-passports">ID Stronghold – to protect your passport</a><br />
<a href="http://blog.wired.com/27bstroke6/2009/02/atm.html">Global ATM theft nets 9 million in one day</a><br />
<a href="http://www.eielson.af.mil/news/story.asp?id=123131336">Airbase installs electronic locks</a>.<br />
<a href="http://www.contactlessnews.com/2009/02/03/nfc-is-more-than-just-payments">NFC enabled locks</a>.<br />
<a href="http://www.sony.net/SonyInfo/News/Press/200902/09-016E/index.html">Sony finger vein biometric authentication</a><br />
<a href="http://www.gigapan.org/viewGigapan.php?id=15374&amp;window_height=596&amp;window_width=1168">Gigapan 1500 mega pixel image of inauguration</a><br />
<a href="http://gigapansystems.com/about.html">Gigapan robotic mount information</a><br />
<a href="http://www.yankodesign.com/2009/01/30/its-a-key-thing/">Key holder</a><br />
<a href="http://www.engadget.com/2009/02/04/ame-105-spy-camera-finds-its-way-into-id-badge-for-nefarious-end/">ID Badge spy cam.</a></p>
<p>Click the link to read the text of the entire podcast.<br />
<span id="more-131"></span></p>
<h2 class="western">Drive by Passport Cloning</h2>
<p style="margin-bottom: 0in" align="justify"><img src="http://lsieducation.com/blog/wp-content/uploads/2009/02/passport-cover-small.jpg" border="0" alt="passport-cover-small.jpg" hspace="9" width="100" height="120" align="left" />We have reported several times that RFID tags can be read from a distance. Reading the RFID tag on an access card or passport is the first step to cloning it. In show number one we talked about methods of RFID  skimming and cloning. One such cloning attack was the California highway toll road passes. Refer to show #1 if you want to review that information. In show number two we mentioned Identity Stroghold, a company that makes secure sleeves for protecting RFID devices from long range snooping.</p>
<p style="margin-bottom: 0in; text-align: justify;">So what follows is a story about a security researcher who recently used components purchased on eBay for less than $250 to do some drive by discovery of RFID enabled devices. In a manner similar to Wardriving where a mobile laptop discovers unsecure wifi network resources, the researcher equipped his vehicle to discover nearby RFID devices and capture the unique identifier code. During a 20 minute drive in downtown San Fancisco he was able to copy the RFID tags of two passports without the knowledge of the passport holder.</p>
<p style="margin-bottom: 0in; text-align: justify;">The cards make use of the RFID equivalent of optical barcodes known as electronic product code tags, which are widely used to track cattle and merchandise as it&#8217;s shipped and then stored in warehouses. Because the technology employs no encryption and can be read from distances of more than a mile, the tags are highly susceptible to cloning and tracking.</p>
<p style="margin-bottom: 0in; text-align: justify;">The snooping system consists of a Symbol brand RFID reader, an antenna mounted to the side of his car,  and a laptop connected to the RFID reader. The laptop runs a Windows application that continuously prompts the RFID reader to look for tags and logs the serial number each time one is detected. While this proof of concept setup has a range of about 30 feet, modifications could increase the range to at least one mile.</p>
<p style="margin-bottom: 0in; text-align: justify;">Government officials say that they have no plans to change the technology used in passport cards because they have increased the processing throughput at border crossings. Given the fact that the passports are provided with protective sleeves, and that the number captured does not reveal personal information about the user, they feel that the system is still relativley safe.</p>
<p style="margin-bottom: 0in; text-align: justify;">Researcher Chris Paget plans to release the software&#8217;s source code during a demonstration at the Shmoocon hacker convention being held this week in Washington DC.</p>
<p style="margin-bottom: 0in; text-align: justify;">So what is our take-away from this story? The point has been made over and over that RFID systems can be read at great distances, and the tags can be cloned. Reading at a distance is useful if you are a truck hijacker who is looking for that load of big screen TV&#8217;s. Cloning is also useful to the bad guys given that Sam&#8217;s Club and others are actively developing RFID enabled cash registers. Even though tag cloning required some equipment, some could argue that it would be easier than counterfeiting a UPC bar code. If your facility is contemplating the use of RFID for any purpose, learn from these stories and take a long hard look at the risks it may pose for your facility.</p>
<p style="margin-bottom: 0in; text-align: justify;">In the future, according to some recently released patent applications,  end users of ID cards, access control cards, or these new RFID passports will need to squeeze a target area activating a switch to allow the card or passport to be read. In the meantime  concerned users should make use of the shielding devices that are currently available.</p>
<h2 class="western">A Global ATM theft nets 9 million in one day</h2>
<p style="text-align: justify;"><img src="http://lsieducation.com/blog/wp-content/uploads/2009/02/atmhand.jpg" border="0" alt="ATM+Hand.jpg" hspace="9" width="183" height="152" align="left" />Wired Threat Level has a story about a  carefully coordinated global ATM heist last November resulted in a one-day haul of $9 million in cash, after a hacker penetrated a server at payment processor RBS WorldPay.</p>
<p style="text-align: justify;">The story is written by <a href="http://en.wikipedia.org/wiki/Kevin_Poulsen">Kevin Poulsen</a>, a well known hacker turned journalist, who once served 4 years for mail, wire &amp; computer fraud.</p>
<p style="text-align: justify;">Wired cites a Fox 5 New York news report that explains that the hacker releived RBS WorldPay of personal information on approximately 1.5 million payroll-card and gift-card customers. Payroll cards are debit cards provided by employers instead of paychecks or direct-deposit.  Account numbers and other data needed to clone the debit cards was also taken during the hacking breach.</p>
<p style="text-align: justify;">Originally the company said it had fraudulent activity on only 100 cards, however the hacker managed to modify the withdrawal limits on those 100 cards, and used a global network of accomplices to drain the cards with repeated rapid-fire withdrawals. More than 130 ATMs in 49 cities from Moscow to Atlanta were hit simultaneously just after midnight Eastern Time on November 8.</p>
<p style="margin-bottom: 0in; text-align: justify;">The story goes on to mention that this is not the first time these payroll card systems have been targeted. In late 2007 a company called iWire lost 5 million dollars in a similar attack that lasted just 2 days, and Citibank lost 2 million from ATM machines in 7-11 stores in New York City.</p>
<p style="margin-bottom: 0in; text-align: justify;">It is interesting and sometimes amusing to sit back and watch the debate over the good and evil done by hackers. What is currently happening to the computer systems we have all come to rely on is very similar to what has been happening to the physical lock industry for hundreds of years. One man builds a lock or security chest and it sets the standard for a few years until another man defeats it. And then a better one is made, and so on and so on. The same is happening in the computer industry. Knowledgeable security practitioners recognize that hackers and lock sport enthusiasts cannot be outlawed and instead, learn from them,   which leads to improvements in security. Think of them as your own free R&amp;D department.</p>
<h2 class="western">Some reasons to consider electronic locks.</h2>
<p style="margin-bottom: 0in; text-align: justify;">A recent story in the news describes how Eielson Air Force base in Alaska has installed card operated electronic locks on the dormitory doors.   The locks, provided by Best Access systems, a division of Stanly, read the residents existing Common Area Access card.</p>
<p style="margin-bottom: 0in; text-align: justify;"><img src="http://lsieducation.com/blog/wp-content/uploads/2009/02/integra5-large.jpg" border="0" alt="integra5-large.jpg" width="123" height="122" align="left" /><br />
Previously the dormitories used traditional mechanical locks and metal keys. The following comments made in the article offer insight as to why these systems are so popular with large facilities.</p>
<p style="margin-bottom: 0in; text-align: justify;">
<ol style="text-align: justify;">
<li>
<p style="margin-bottom: 0in" align="justify">The system offers better key control because the key card cannot be duplicated at the local hardware store.</p>
</li>
<li>
<p style="margin-bottom: 0in" align="justify">The system also offers more security with regard to methods of entry,.</p>
</li>
<li>
<p style="margin-bottom: 0in" align="justify">The system is more cost effective to manage both in time and money.</p>
</li>
</ol>
<p style="margin-bottom: 0in; text-align: justify;">One major area of cost management is the replacement of lost keys. With the new system, when a card is lost, the airman is issued a replacement card which invalidates the code on the lost card. This process can be handled in a few minutes by the dorm management department. Previously, lost keys required a call to a locksmith to change the lock, a process which took a few hours to complete.</p>
<p style="margin-bottom: 0in; text-align: justify;">Facilities contemplating such a purchase should add up the cost of ownership and ongoing maintenance of both high security mechanical systems and stand alone card access systems and use the resulting data as part of your decision factors. Locksmiths who are not currently installing such systems should seriously consider adding them to their areas of expertise or risk losing valuable customers who decide to install electronic access control.</p>
<h2 class="western" style="page-break-before: always; text-align: justify;">NFC Enabled Electronic Locks.</h2>
<p style="text-align: justify;"><img src="http://lsieducation.com/blog/wp-content/uploads/2009/02/ving-card.jpg" border="0" alt="ving_card.jpg" hspace="9" width="170" height="135" align="left" />Near Field Communications, NFC for short,  is a next generation technology touted as a replacement for contactless cards or potentially even the entire contents of your wallet.  NFC will enable a phone to carry all your credit cards, loyalty cards, maybe eventually even your driver license.</p>
<p style="text-align: justify;">NFC can support a wide range of applications such as opening a door, logging into your computer, signing on to the Internet, or download maps or directions from a kiosk or display.</p>
<p style="text-align: justify;">Co-developed in 2004 by NXP Semiconductors and Sony, it is a short-range wireless technology that evolved from existing contactless technologies. NFC is supposed to simplify the way consumer devices interact with one another, helping people speed connections, receive and share information and even make fast and secure payments.</p>
<p style="text-align: justify;">To encourage development of “cool” NFC applications, the NFC Forum organization conducted an annual contest to encourage out-of-the-box developments.</p>
<p style="text-align: justify;">The first place winner  in this year’s competition was VingCard, an ASSA Abloy company. VingCard developed an NFC-enabled lock for hotel rooms. The system  enables guests to bypass the check-in process and unlock their hotel room doors using their phones.</p>
<p style="text-align: justify;">The VingCard system was designed to streamline the checkin and check out process by eliminating the need for a guest to stand in line at the front desk. In fact, the hotel chain can sell the room to the guest over their web site, and then encode the room data via an encrypted text message exchange when the guest indicates he has arrived, either at the airport, in the taxi, or the lobby of the hotel.</p>
<p style="text-align: justify;">It doesn&#8217;t take much imagination to see how such a system could be deployed for a commercial facility using NFC for access control. Global text messages to all authorized devices could be used to update the system and change access privileges on the fly, for an access system that had buildings located anywhere in the world (where there is cell phone reception of course).</p>
<h2 class="western">Sony Develops Biometric Finger Vein Authentication.</h2>
<p style="margin-bottom: 0in; text-align: justify;">Sony Corporation today announced the development of a finger vein authentication technology. This technology offers quick response and high accuracy and comes in a compact size designed for mounting on  personal computers or mobile phones.</p>
<p style="margin-bottom: 0in; text-align: justify;">Sony claims that compared to the other biometric authentication techniques, vein authentication technology achieves higher accuracy for  personal identification and higher forgery resistance because it uses the veins inside the finger. Finger vein patterns differ from person to person and finger to finger, and it is said that they do not change over the years.</p>
<p style="margin-bottom: 0in; text-align: justify;">The design uses a unique method where a CMOS sensor diagonally captures scattered light inside the finger veins, resulting in a design that occupies a single planar surface resulting in a design small enough for mobile devices.</p>
<p><img src="http://lsieducation.com/blog/wp-content/uploads/2009/02/qfhh7c00000lzdst.jpg" border="0" alt="qfhh7c00000lzdst.jpg" width="198" height="201" align="left" /></p>
<p style="margin-bottom: 0in; text-align: justify;">The vein pattern is extracted from the captured finger vein image, and data is compressed and corrected to compensate for slightly differing finger positions.</p>
<p style="margin-bottom: 0in; text-align: justify;">Sony claims a less than 0.1% for the False Rejection Rate and less than 0.0001% for the False Acceptance Rate. They expect to  commercialize the technology within the 2009 fiscal year.</p>
<p style="margin-bottom: 0in; text-align: justify;">So what can we take away from this story? Continuing advancements in user friendly, simple to use, and cost effective biometric authentication devices are  certainly welcome in the security industry. It is even more useful when they are deployed, and consequently debugged in such heavily used consumer devices as laptops and cell phones. Further, the application in such popular devices lowers many of the barriers to implementation confronted by security practitioners.</p>
<p style="margin-bottom: 0in; text-align: justify;">
<h2 class="western" style="page-break-before: always">Panning camera has security applications</h2>
<p style="text-align: justify;">You may have already seen the <a href="http://www.gigapan.org/viewGigapan.php?id=15374&amp;window_height=596&amp;window_width=1168">spectacular image of President Obama’s inauguration</a> that was taken by NY photographer David Bergman. If not, head over to the website linked in our show notes and take a look. It is incredible in size, scope, and resolution. He made the special panoramic image from the north press platform during the inaugural address. It&#8217;s made up of 220 images stitched together into a final image size of 1,500 megapixels.</p>
<p style="text-align: justify;">The image was created using a Canon PowerShot G10, a 15 megapixel compact digicam with a 5x zoom that retails for about $260, and the GigaPan Epic robotic mount.</p>
<p style="text-align: justify;">The GigaPan is a robotic camera mount that works with most point and shoot cameras to create huge panoramas. It works in conjunction with included stiching software that joins all the smaller images into one large image, and the GigaPan.org website for sharing the images with others.</p>
<p style="text-align: justify;"><img src="http://lsieducation.com/blog/wp-content/uploads/2009/02/picture-2.png" border="0" alt="Picture 2.png" width="178" height="180" align="left" />You simply attach your camera and set the upper left and lower right corner of the scene you want to capture. The robot works out how many pictures it needs to take, and robotically positions the camera and snaps the shutter.  And it does all that for the incredibly low price of  $379.00, available directly from GigaPan Systems.</p>
<p style="text-align: justify;">GigaPan Systems was established in 2008 as a commercial spin-off of a collaboration between NASA and Carnegie Mellon University. The GigaPan Imager uses the same technology that was used by the two Mars Exploration Rovers, Spirit and Opportunity, to collect amazing panoramic images of Mars.</p>
<p style="text-align: justify;">Of course the security applications for this device are enormous. If you go to the web page in the show notes and look at the image you can see that you can use the web page controls to zoom in on any part of the crowd. Just for fun, count the number security people on the roof tops, or zoom in and read the sheet music in the orchestra pit. Obviously this could be a powerful tool for capturing images of large events for later analysis, and at a price that won&#8217;t break even the most modest security budget.</p>
<h2 class="western">Yet another way to not lose your keys.</h2>
<p style="margin-bottom: 0in; text-align: justify;"><img src="http://lsieducation.com/blog/wp-content/uploads/2009/02/key-thing2.jpg" border="0" alt="key_thing2.jpg" hspace="9" width="80" height="105" align="left" />In the just for fun department, the folks at Yanko Design give us a new design for a common problem, misplacing your keys.  Gone are the days of hanging your keys on a hook, tossing them on the counter, or dropping them in a drawer, attaching them to an electronic finder, or worse doing none of this and forgetting where you put them. The #8 KeyThing circumvents that fact of life by giving you one place to keep all your keys. The lady bug looking contraption is a simple piece of rubber with grip port holes. As long as you remember where you mounted it, losing your keys should be a thing of the past. Check out the link to the web site on our show notes page.</p>
<h2 class="western">Our Weekly Spy Cam Product</h2>
<p style="margin-bottom: 0in; text-align: justify;">And finally, continuing what seems to be a weekly discovery in small spy camera type devices, we found a new one on the web site Engadget. It is a spy camera disguised as a personal ID badge with a forward looking 1.3 megapixel camera that records a 352&#215;288 image at 15 frames per second. It has 4GM of memory and a USB port and reportedly sells for about $155 US. Put your picture and the phone company logo on the front, break out your hard hat and clipboard, and you could probably roam anywhere you want recording lots of video and audio.</p>
<h2 class="western">GSA Approved!</h2>
<p style="margin-bottom: 0in" align="justify">And in our final story today we are happy to report that Lockmasters Security Institute is now fully approved by the General Services Administration as a Certified Training Facility for the GSA CERTIFIED Safe &amp; vault Technician Course. With over 400,000 GSA security containers in use today, this is an ideal course for any U.S. military, government and commercial locksmith. You will learn all the skills required to service, maintain and inspect GSA approved security containers. In our GSA Inspector Certification course you will Learn how to confirm if a GSA container or vault door is up to standards, and if it can be labeled as GSA approved. You will be certified  to inspect and re-certify any GSA approved container if it meets specifications.</p>
]]></content:encoded>
			<wfw:commentRss>http://lsieducation.com/blog/2009/02/psn009-drive-by-passport-cloning-atm-thefts-nfc-enabled-locks-and-more/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://media.libsyn.com/media/psnlsi/PSN009.mp3" length="18950187" type="audio/mpeg" />
		<itunes:duration>19:44</itunes:duration>
		<itunes:subtitle>In this episode we discuss drive-by passport cloning, huge ATM thefts, NFC enabled electronic locks, a new biometric idea to replace fingerprint readers, 1500 Megapixel ...</itunes:subtitle>
		<itunes:summary>In this episode we discuss drive-by passport cloning, huge ATM thefts, NFC enabled electronic locks, a new biometric idea to replace fingerprint readers, 1500 Megapixel images for security surveillance, and yet another cool miniature spy cam. We also make note that Lockmasters Security Institute is now fully approved by the General Services Administration (GSA) as a Certified Training Facility for the GSA CERTIFIED Safe &#38; Vault Technician Courses. With over 400,000 GSA containers in use, can you afford not to become certified?

Show Links
Driveby passport cloning
Shmoocon DC – passport hack revealed
RFID pressure switch patent
ID Stronghold – to protect your passport
Global ATM theft nets 9 million in one day
Airbase installs electronic locks.
NFC enabled locks.
Sony finger vein biometric authentication
Gigapan 1500 mega pixel image of inauguration
Gigapan robotic mount information
Key holder
ID Badge spy cam.

Click the link to read the text of the entire podcast.

Drive by Passport Cloning
We have reported several times that RFID tags can be read from a distance. Reading the RFID tag on an access card or passport is the first step to cloning it. In show number one we talked about methods of RFID  skimming and cloning. One such cloning attack was the California highway toll road passes. Refer to show #1 if you want to review that information. In show number two we mentioned Identity Stroghold, a company that makes secure sleeves for protecting RFID devices from long range snooping.
So what follows is a story about a security researcher who recently used components purchased on eBay for less than $250 to do some drive by discovery of RFID enabled devices. In a manner similar to Wardriving where a mobile laptop discovers unsecure wifi network resources, the researcher equipped his vehicle to discover nearby RFID devices and capture the unique identifier code. During a 20 minute drive in downtown San Fancisco he was able to copy the RFID tags of two passports without the knowledge of the passport holder.
The cards make use of the RFID equivalent of optical barcodes known as electronic product code tags, which are widely used to track cattle and merchandise as it's shipped and then stored in warehouses. Because the technology employs no encryption and can be read from distances of more than a mile, the tags are highly susceptible to cloning and tracking.
The snooping system consists of a Symbol brand RFID reader, an antenna mounted to the side of his car,  and a laptop connected to the RFID reader. The laptop runs a Windows application that continuously prompts the RFID reader to look for tags and logs the serial number each time one is detected. While this proof of concept setup has a range of about 30 feet, modifications could increase the range to at least one mile.
Government officials say that they have no plans to change the technology used in passport cards because they have increased the processing throughput at border crossings. Given the fact that the passports are provided with protective sleeves, and that the number captured does not reveal personal information about the user, they feel that the system is still relativley safe.
Researcher Chris Paget plans to release the software's source code during a demonstration at the Shmoocon hacker convention being held this week in Washington DC.
So what is our take-away from this story? The point has been made over and over that RFID systems can be read at great distances, and the tags can be cloned. Reading at a distance is useful if you are a truck hijacker who is looking for that load of big screen TV's. Cloning is also useful to the bad guys given that Sam's Club and others are actively developing RFID enabled cash registers. Even though tag cloning required some equipment, some could argue that it would be easier than counterfeiting a UPC bar code. If your facility is contemplating the use of RFID for any purpose, learn from these stories</itunes:summary>
		<itunes:keywords>locksmith, lockmasters, training, vault, security, homeland, law enforcement, military</itunes:keywords>
		<itunes:author>Jon Payne, Sr., CML</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>yes</itunes:block>
	</item>
		<item>
		<title>PSN009E &#8211; Drive by passport cloning, ATM thefts, NFC Enabled Locks and more.</title>
		<link>http://lsieducation.com/blog/2009/02/psn009e-drive-by-passport-cloning-atm-thefts-nfc-enabled-locks-and-more/</link>
		<comments>http://lsieducation.com/blog/2009/02/psn009e-drive-by-passport-cloning-atm-thefts-nfc-enabled-locks-and-more/#comments</comments>
		<pubDate>Sat, 07 Feb 2009 22:01:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Electronics]]></category>
		<category><![CDATA[Hacks]]></category>
		<category><![CDATA[Locks]]></category>
		<category><![CDATA[LSI]]></category>
		<category><![CDATA[New Products]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://lsieducation.com/blog/?p=140</guid>
		<description><![CDATA[(Enhanced Podcast) In this episode we discuss drive-by passport cloning, huge ATM thefts, NFC enabled electronic locks, a new biometric idea to replace fingerprint readers, 1500 Megapixel images for security surveillance, and yet another cool miniature spy cam. We also make note that Lockmasters Security Institute is now fully approved by the General Services Administration [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">(Enhanced Podcast) In this episode we discuss drive-by passport cloning, huge ATM thefts, NFC enabled electronic locks, a new biometric idea to replace fingerprint readers, 1500 Megapixel images for security surveillance, and yet another cool miniature spy cam. We also make note that Lockmasters Security Institute is now fully approved by the General Services Administration (GSA) as a Certified Training Facility for the GSA CERTIFIED Safe &amp; Vault Technician Courses. With over 400,000 GSA containers in use, can you afford not to become certified?</p>
<p style="text-align: justify;">This is the <a href="http://support.apple.com/kb/HT1597">enhanced version</a> of the podcast with embedded images and chapter markers much like a DVD. See <a href="http://lsieducation.com/blog/2009/02/psn009-drive-by-passport-cloning-atm-thefts-nfc-enabled-locks-and-more/" target="_self">PSN009</a> for the show links and the full text of the podcast.</p>
]]></content:encoded>
			<wfw:commentRss>http://lsieducation.com/blog/2009/02/psn009e-drive-by-passport-cloning-atm-thefts-nfc-enabled-locks-and-more/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://media.libsyn.com/media/psnlsi/PSN009E.m4a" length="16758212" type="audio/x-m4a" />
		<itunes:duration>19:44</itunes:duration>
		<itunes:subtitle>(Enhanced Podcast) In this episode we discuss drive-by passport cloning, huge ATM thefts, NFC enabled electronic locks, a new biometric idea to replace fingerprint readers, ...</itunes:subtitle>
		<itunes:summary>(Enhanced Podcast) In this episode we discuss drive-by passport cloning, huge ATM thefts, NFC enabled electronic locks, a new biometric idea to replace fingerprint readers, 1500 Megapixel images for security surveillance, and yet another cool miniature spy cam. We also make note that Lockmasters Security Institute is now fully approved by the General Services Administration (GSA) as a Certified Training Facility for the GSA CERTIFIED Safe &#38; Vault Technician Courses. With over 400,000 GSA containers in use, can you afford not to become certified?
This is the enhanced version of the podcast with embedded images and chapter markers much like a DVD. See PSN009 for the show links and the full text of the podcast.</itunes:summary>
		<itunes:keywords>locksmith, lockmasters, training, vault, security, homeland, law enforcement, military</itunes:keywords>
		<itunes:author>Jon Payne, Sr., CML</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>yes</itunes:block>
	</item>
		<item>
		<title>PSN008E &#8211; Dangerous USB, Covert Cameras and Monster Shredders</title>
		<link>http://lsieducation.com/blog/2009/01/psn008e-dangerous-usb-covert-cameras-and-monster-shredders/</link>
		<comments>http://lsieducation.com/blog/2009/01/psn008e-dangerous-usb-covert-cameras-and-monster-shredders/#comments</comments>
		<pubDate>Fri, 30 Jan 2009 17:16:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Computer]]></category>
		<category><![CDATA[Electronics]]></category>
		<category><![CDATA[Locks]]></category>
		<category><![CDATA[LSI]]></category>
		<category><![CDATA[New Products]]></category>
		<category><![CDATA[Podcast]]></category>

		<guid isPermaLink="false">http://lsieducation.com/blog/?p=115</guid>
		<description><![CDATA[(Enhanced Podcast) In this episode we look at 10 items in the news including why the Dod has temporarily banned the use of USB thumb drives, how mobile phones can be the &#8216;smoking gun&#8217;, how Ford trucks can go on-line, about how the Kwikset Smartkey is pickproof, bump proof, and has record sales, a high [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">(Enhanced Podcast) In this episode we look at 10 items in the news including why the Dod has temporarily banned the use of USB thumb drives, how mobile phones can be the &#8216;smoking gun&#8217;, how Ford trucks can go on-line, about how the Kwikset Smartkey is pickproof, bump proof, and has record sales, a high tech ATM debit card skimmer, home made drug smuggling submarines, some sneaky covert cameras, and a shredder that eats engine blocks for breakfast.</p>
<p>This is the <a href="http://support.apple.com/kb/HT1597">enhanced version</a> of the podcast with embedded images and chapter markers much like a DVD. See <a href="http://lsieducation.com/blog/2009/01/psn008-dangerous-usb-covert-cameras-and-monster-shredders/">PSN008</a> for the show links and the full text of the podcast.</p>
]]></content:encoded>
			<wfw:commentRss>http://lsieducation.com/blog/2009/01/psn008e-dangerous-usb-covert-cameras-and-monster-shredders/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://media.libsyn.com/media/psnlsi/PSN008E.m4a" length="18411903" type="audio/x-m4a" />
		<itunes:duration>21:41</itunes:duration>
		<itunes:subtitle>(Enhanced Podcast) In this episode we look at 10 items in the news including why the Dod has temporarily banned the use of USB thumb ...</itunes:subtitle>
		<itunes:summary>(Enhanced Podcast) In this episode we look at 10 items in the news including why the Dod has temporarily banned the use of USB thumb drives, how mobile phones can be the 'smoking gun', how Ford trucks can go on-line, about how the Kwikset Smartkey is pickproof, bump proof, and has record sales, a high tech ATM debit card skimmer, home made drug smuggling submarines, some sneaky covert cameras, and a shredder that eats engine blocks for breakfast.

This is the enhanced version of the podcast with embedded images and chapter markers much like a DVD. See PSN008 for the show links and the full text of the podcast.</itunes:summary>
		<itunes:keywords>Business, Computer, Electronics, Locks, LSI, New Products, Podcast</itunes:keywords>
		<itunes:author>Jon Payne, Sr., CML</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>yes</itunes:block>
	</item>
		<item>
		<title>PSN007 &#8211; Master Lock &#8211; AXIS &#8211; a unique padlock</title>
		<link>http://lsieducation.com/blog/2009/01/psn007-master-lock-axis-a-unique-padlock/</link>
		<comments>http://lsieducation.com/blog/2009/01/psn007-master-lock-axis-a-unique-padlock/#comments</comments>
		<pubDate>Mon, 26 Jan 2009 04:15:41 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Locks]]></category>
		<category><![CDATA[LSI]]></category>
		<category><![CDATA[New Products]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://lsieducation.com/blog/?p=102</guid>
		<description><![CDATA[In this episode we take a close look at a new padlock soon to be released by Master Lock. Named Axis, this lock was invented by Yehonatan Knoll, an Israeli engineer. Included in this podcast is an interview with Yeshai Knoll, the CEO of Knollan, about the concept and development of this new lock. Also [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">In this episode we take a close look at a new padlock soon to be released by Master Lock. Named Axis, this lock was invented by Yehonatan Knoll, an Israeli engineer. Included in this podcast is an interview with Yeshai Knoll, the CEO of Knollan, about the concept and development of this new lock. Also included is an interview with Michael Huebler, a German lock sport enthusiast who dissected this lock and analyzed how it works. Click “Continue Reading” for the full script of the show.</p>
<h3>Show Links</h3>
<dl>
<dt><a href="http://www.knollan.com/home.asp">Welcome to Knollan a new locking mechanism</a> </dt>
<dt><a href="http://www.google.com/patents?id=h1sQAAAAEBAJ&amp;pg=PA2&amp;dq=6,718,803&amp;source=gbs_selected_pages&amp;cad=1_1#PPA11,M1">patent document</a> </dt>
<dt><a href="http://www.blackbag.nl/?p=183">blackbag » Michael Huebler’s masterlock article on Toool.nl and discussion thread</a> </dt>
<dt><a href="http://media.libsyn.com/media/psnlsi/The_New_Master_Lock_Combination_Padlock_V1.0.pdf" target="_blank">Michael Huebler&#8217;s original analysis.</a></dt>
<dt><a href="http://media.libsyn.com/media/psnlsi/AxisVisualizer_V1.0_p.swf" target="_blank">Lock Mechanism Visualizer</a></dt>
<dt>
</dt>
</dl>
<dl>
<dt><span id="more-102"></span></dt>
</dl>
<p>Pro Security News &#8211; PSN007 Script</p>
<h3>Master Lock to launch AXIS Combination Padlock</h3>
<p>It is not often that we get to report on a new product that very few people have seen, or even heard about. Today is one of those days. Consequently this show will focus on one topic and we will resume our news briefing next week.<br />
Master Padlock will be launching a new combination padlock in May of 2009. Now ordinarily, a new padlock is not really newsworthy, however this product is very different. It breaks all the rules as you know them.<br />
The lock is called Axis, and it presents an entirely  new user interface for unlocking a lock. When you think of a traditional school or gym-locker combination lock, you probably visualize a dial with 30 numbers, or small wheels with 10 numbers each. Now imagine a lock that can be could be opened in complete darkness, with one hand, and one finger, and without a key, in 2 seconds or less.<br />
That is exactly what this new patented mechanism delivers. It was invented by Yehonatan Knoll and licensed to Master Lock company. Mr. Knoll is a principle in the design company of Knollan located in Israel.<br />
The AXIS presents an entirely new interface for opening a padlock. It is the only padlock I know of that could be used by a blind person. Instead of a dial to turn and numbers to set, there is a knob which can slide in 4 directions, top, bottom, left &amp; right.</p>
<h3>Opening the Lock</h3>
<p>To operate the lock, you must first clear it by pushing down on the shackle. The factory code is TOP, BOTTOM, LEFT, &amp; RIGHT, so you slide the spring loaded knob sequentially in each direction and then pull the shackle to open.</p>
<h3>Changing the Combination</h3>
<p>The user can set a new combination by first opening the lock, and sliding the lever on the back of the lock to the “R” position. Next, depress the shackle to clear the lock, and then enter a new combination.<br />
There is NO LIMIT to the number of movements you can make with the slide knob. It is limited only by what you can remember. Furthermore, any movement can be repeated any number of times. For example, you could have a combination that required only one down movement, or it could, for example, require 10 down movements.<br />
The lock I have described here has no numbers, however a visit to the website of the inventor shows how numbers could be associated with the direction of movement. For example, TOP could be labeled with the number 1, Right with the number 2, etcetera. The illustration on the website actually shows each direction associated with a grouping of numbers  so as to use all numbers from 0 through 9.<br />
Another method to help remember combinations could be to use letters to correspond to the direction of movement. The letters could appear in an acronym or word that the user can remember. For example, if we label the direction of movement North, South, East &amp; West, the word NEWS could be used as the combination. If you add Up, Down, Top, Bottom, Left &amp; Right, then you increase the words that could be used to help remember the sequence.</p>
<h3>How it works</h3>
<p>A very good description  and technical analysis of this lock was written by Michael Huebler from Germany. There is a link to his paper on our website. It includes photographs of the inside mechanism, and a well written analysis of how the mechanism operates, and some thoughts about the number of possible combinations.<br />
Michael also created an animated visualization to help understand what is going on when you move the knob. You can interact with this program from any web browser that supports Flash objects. That link is also on our website along with a link to the original patent drawings, and to the website of the inventor.</p>
<h3>Conclusions</h3>
<p>From a physical strength point of view, the construction of this padlock indicates that the intended market is areas such as school and gym lockers. As to manipulation or other methods of surreptitious entry, I’m sure the locksport community and others will let us know soon enough. Regardless of that outcome it is very refreshing to see  a new security design that is clearly new and innovative. As you will hear in the interview in a few moments, it is possible to create a more secure version of this idea by adding more disks to the design, and by changing the plastic parts to metal parts at an increased cost of course.</p>
<h3>Interview</h3>
<p>What follows next is an interview I had with Yeshai Knoll, the CEO of Knollan, the company that was founded by the inventor, Yehonatan Knoll and his father, Yeshai, to develop and market this idea.<br />
The next interview is with Michael Huebler from Germany. Michael is a locksport enthusiast who obtained a sample of this padlock at last years hardware show in cologne germany. He wrote a detailed explanation of how it works which can be found as a link in the show notes.<br />
Michael and I ended our conversation a few minutes later &amp; I am most grateful to him for spending some time with us to discuss his finding with this lock. During our conversation we discovered that our sample locks operated differently. His sample lock and his simulator both show that a lock set to the cod of up, down, left &amp; right can also be opened with left left right, however my sample padlock does not behave the same way. I will look into this and report back when I have an answer. In the meantime, watch for the release of this lock, I think you will enjoy playing with one. It truly is unique.</p>
]]></content:encoded>
			<wfw:commentRss>http://lsieducation.com/blog/2009/01/psn007-master-lock-axis-a-unique-padlock/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
			<enclosure url="http://media.libsyn.com/media/psnlsi/PSN007.mp3" length="34565143" type="audio/mpeg" />
		<itunes:duration>36:00</itunes:duration>
		<itunes:subtitle>In this episode we take a close look at a new padlock soon to be released by Master Lock. Named Axis, this lock was invented ...</itunes:subtitle>
		<itunes:summary>In this episode we take a close look at a new padlock soon to be released by Master Lock. Named Axis, this lock was invented by Yehonatan Knoll, an Israeli engineer. Included in this podcast is an interview with Yeshai Knoll, the CEO of Knollan, about the concept and development of this new lock. Also included is an interview with Michael Huebler, a German lock sport enthusiast who dissected this lock and analyzed how it works. Click “Continue Reading” for the full script of the show.

Show Links
 Welcome to Knollan a new locking mechanism  patent document  blackbag » Michael Huebler’s masterlock article on Toool.nl and discussion thread  Michael Huebler's original analysis. Lock Mechanism Visualizer 
    Pro Security News - PSN007 Script
Master Lock to launch AXIS Combination Padlock
It is not often that we get to report on a new product that very few people have seen, or even heard about. Today is one of those days. Consequently this show will focus on one topic and we will resume our news briefing next week.
Master Padlock will be launching a new combination padlock in May of 2009. Now ordinarily, a new padlock is not really newsworthy, however this product is very different. It breaks all the rules as you know them.
The lock is called Axis, and it presents an entirely  new user interface for unlocking a lock. When you think of a traditional school or gym-locker combination lock, you probably visualize a dial with 30 numbers, or small wheels with 10 numbers each. Now imagine a lock that can be could be opened in complete darkness, with one hand, and one finger, and without a key, in 2 seconds or less.
That is exactly what this new patented mechanism delivers. It was invented by Yehonatan Knoll and licensed to Master Lock company. Mr. Knoll is a principle in the design company of Knollan located in Israel.
The AXIS presents an entirely new interface for opening a padlock. It is the only padlock I know of that could be used by a blind person. Instead of a dial to turn and numbers to set, there is a knob which can slide in 4 directions, top, bottom, left &#38; right.
Opening the Lock
To operate the lock, you must first clear it by pushing down on the shackle. The factory code is TOP, BOTTOM, LEFT, &#38; RIGHT, so you slide the spring loaded knob sequentially in each direction and then pull the shackle to open.
Changing the Combination
The user can set a new combination by first opening the lock, and sliding the lever on the back of the lock to the “R” position. Next, depress the shackle to clear the lock, and then enter a new combination.
There is NO LIMIT to the number of movements you can make with the slide knob. It is limited only by what you can remember. Furthermore, any movement can be repeated any number of times. For example, you could have a combination that required only one down movement, or it could, for example, require 10 down movements.
The lock I have described here has no numbers, however a visit to the website of the inventor shows how numbers could be associated with the direction of movement. For example, TOP could be labeled with the number 1, Right with the number 2, etcetera. The illustration on the website actually shows each direction associated with a grouping of numbers  so as to use all numbers from 0 through 9.
Another method to help remember combinations could be to use letters to correspond to the direction of movement. The letters could appear in an acronym or word that the user can remember. For example, if we label the direction of movement North, South, East &#38; West, the word NEWS could be used as the combination. If you add Up, Down, Top, Bottom, Left &#38; Right, then you increase the words that could be used to help remember the sequence.
How it works
A very good description  and technical analysis of this lock was written by Michael Huebler from Germany. There is a link to his paper on our website. It includes photographs of the inside mechanism, and a</itunes:summary>
		<itunes:keywords>Locks, LSI, New Products, Podcast, Uncategorized</itunes:keywords>
		<itunes:author>Jon Payne, Sr., CML</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
	</channel>
</rss>

