In my office complex, we have a bunch of security guards who _check_ badges of people who enter the building (My building houses about 8-9 companies). If you don't have a badge then the guard calls the office you claim to be part of to ensure you have access, and then issues a temp badge.
A couple months ago, I forgot my badge at home, but didn't want to go through the hassle of getting a temp badge, so I flashed my driver's license at the guard (which is roughly the same size as my ID badge) and he simply waved me through.
I told my colleagues this, and since then we have a silly game where we try to get in using ridiculous cards. Most recently, we have people who have flashed blood donation cards (a card that acknowledges that you donated blood on so and so date), a credit card and a folded bookmark and successfully gotten into the complex.
While this is a running joke, really goes to show how lax manual security can be (Especially because once you are on my floor, you can easily tailgate your way into my office).
TL;DR Most of our security systems work on implicit trust more than anything else.
I used to be a security guard after I left the army (no skills in civvi street to get a better job).
Couple of things come to mind reading this. One that security guard is probably getting paid a pittance to do that job and you get what you pay for. Two the guard recognises you and your colleagues, knows you work there and doesn't really care that you're playing silly games because on their wage it's not worth the hassle pulling you up for you to get all high and mighty about the inconvenience of a lowly security guard daring to question you. Three that single guard, whilst ostensibly there for "security" is really just there for show, there's no way a single lowly paid guard can possibly provide security for a building housing 8 or 9 companies even with the best intentions.
My experience as a guard was that the employees of the companies within the building treated me with contemptuous distain until something happened at which point it was righteous anger.
> My experience as a guard was that the employees of the companies within the building treated me with contemptuous distain until something happened at which point it was righteous anger.
:(
It's good to see (from the existence of these new articles) that companies are slowly starting to realize that security isn't something to sweep under the carpet and hold in distain.
What do you mean by "righteous anger" though? It sounds like there's a potentially interesting story (or three) hiding in there...
I once worked on a building that was essentially ruled by the office manager (henceforward to be referred to a the wicked witch, WW for short) of one of the buildings companies. The building manager would physically shake everytime she was near.
Anyway to cut a long story short I went to the toilet without asking (yes you heard that right) and came back to find this WW at my desk basically vibrating with righteous rage. An argument ensues which ends up with WW storming off to make a complaint about me going to the toilet and my "bad" attitude which according to WW left to whole building insecure.
Up comes the building manager. I had to call him when I needed the toilet from now on.
Anyway I had noticed that the vast majority of the employees of the office WW managed had invalid passes, they were meant to have photos and employee numbers, but practically all had worn away. So I started to do my job "properly" as per the instructions set forth by WW. Every one with an invalid pass had it removed and they could not get back to work, WW was called to verify identity and she would just give them their pass back and allow them in. WW was not impressed. This lasted until lunch when no one got back into the office. They were queuing out into the street. WW was livid and tried to publicly ridicule me, just a lowly security guard messing thing up.
By the end of our second argument during which I was overly polite in tesponse to the screaming banshee the WW had turned into it was obvious she had lost.
End result. All employees allowed back into work after reissue of invalid I'd cards, I was allowed to go to the toilet when I wanted, I was sacked from that building that evening.
Have you considered (or do you) post(ing) this sort of thing to https://reddit.com/r/talesfromsecurity? This kind of thing would definitely be very well received.
This also sounds like IT. It seems that security and tech are considered to be nothing but cost centers. And then the world can't stop laughing at the string of things that happened to Equifax in a row....
I wonder if the security guards probably notice but are more interested in avoiding confrontation. I'd hate harassing someone who probably won't cause any trouble, and having to potentially get into an argument, where they'll likely belittle my position and make me feel like a shitty person for doing my job.
I was a bank teller during college, and would be occasionally berated by people when I'd ask to check their ID when they were withdrawing money. I always asked if they'd prefer I let anyone trying to take money out of their account do so w/o checking photo ID. One guy swore he was going to get me fired for not letting him take money out of his account because he forgot his wallet at his desk.
The point was that it's not the entire purpose of having the security guard. The building management wants to "provide security" to its tenants as a feature they are willing to pay for. The tenants, for their part, want "security" but not the inconvenience of being "harrassed" by the guards when they forget their purse or whatever.
Guards know this too, and given the choice between letting someone through who you are pretty sure is legitimate and potentially starting a fight which will generate a complaint, they'll "do the best they can" and just wave people through.
Motivations interact in funny ways, and the parameters aren't like software: they're hidden and surprising.
Not for a shared building guard who works for a property company. They are there to keep rifraff and salesmen out.
Look at government and large corporate entities for how to address this. Visitor conference rooms are on the ground floor or away from the office environment. There’s a receptionist who controls access to the employee area, and identification is captured and associated with a staffer for both signin and signout.
Devils advocate, they might simply know your face.
I worked in a 5000 person building for a year, left, and went back a year later for a christmas party. The shared reception still remembered who I was without being told and were able to guess who I was visiting.
I work at a place in the centre of a large city in the UK. Security is hot on badges. I especially know this as I smoke, so going downstairs every couple of hours needed a signing in/out session. To be fair it reduced my habit quite a bit.
Now i've got a proper badge - I can flash anything I like, including my drivers license, or my debit card. The mere act of coyly moving something on a lanyard to them is sufficient, especially now i've explained that i've got noise cancelling headphones so I sometimes cannot hear.
The best bit? There are government departments in the building on a floor below us.
Even better - I used to work at a company that used to be part of the security services in the UK but were spun-out. They still work with the doughnut down the road.
In heightened security times they do random checks of cars - mirrors underneath, etc. All I had to do was say "you checked me yesterday" and they'd not bother.
This is a case where the Nuremberg defence is very useful. If you have explicit policies that are consistently followed, you take away most of the social cost and can even make breaking policy the more difficult choice.
The problems occur in dysfunctional organisations where senior management expect to be exempt from their own rules. Expecting the rules to be bent for your own convenience gives your subordinates tacit permission to bend the rules. Someone who has bent the rules for their boss is far more likely to bend the rules for their buddy. If you're asking people to do inconvenient things, you have to lead by example.
Yes, just look at the example provided by OP. He noticed a security flaw and instead of trying to do something about it he and his companions made a game of exploiting this flaw as much as possible. The employees don't want the inconvenience of actual security.
If I saw that behavior in a manager who was not in my direct reporting chain I would probably let hr know. but having worked mostly govt contract, pharma, and finance I'm used to rfid badges-- not exactly top security tech-- but it, and photos of employees stored in the system, solve the enployee badge issue.
But the security guard is being paid to challenge you, the social cost is off-set by their wages and you'd have to be an ass to take umbrage at a security guard asking for your pass at the entrance to a secure facility.
My pass used to be checked every day for years, in an office of only 1k people, and a line-manager was the only person who could sign you in without it.
Living in a parliamentary democracy and not being an American citizen, “our President” is literally not my president. Are you referring to the American President, Mr. Donald Trump?
I made a little experiment like that myself when I was studying for my Masters. In the town where I live there is a bus card system that uses scratch cards. You get a card with dates (1-31), months and four years (say 2012 to 2016) and you're responsible yourself for scratching off the seven days, month and year when you intend to use the card. So, if you want to use the card starting next Monday, you'd scratch off dates 23 to 29, October and 2017. Then you show it to the bus driver when you board the bus. The understanding is that if you scratch off the wrong days, you can't use the card.
Obviously, mistakes can and do happen. A couple of times I noticed I had scratched off the wrong days or month, or even year. Once I scratched off eight days. One of those mistakes (can't remember which) was noticed by a driver, but most seemed oblivious to the fact my card was irregular, at least (if not totally invalid).
So I decided to make my little experiment: I kept buying and scratching (correctly) a new card each week, but I also kept on me the previous week's card and showed this one to the driver. Then I marked a tick on the card for each time I was waved through without a batting of an eylid. I got about a dozen cards like that, each with a week's worth of ticks or so. I got caught exactly once (at which point I just said "oops, mistake" and took out the right card).
Outcome: we have refuted the null hypothesis that people see what they're looking at.
> we have refuted the null hypothesis that people see what they're looking at.
I remember a police officer pulling over my parents car, asking for the vehicle papers, checking them for 2 good minutes, and saying everything was fine, we were free to go.
After a few kilometres, my father suddenly noticed that he had given the copper the papers of a totally different car than the one in which we were...
It is like at the border, when customs officers flip the pages of your passport while looking at you. They spend as much time on white pages than on the ones that matter; in fact they just watch you and extend the time they watch you by pretending to check something, hoping their magical skills will allow them to detect if you get nervous because you are guilty of something.
When my friends and I all first turned 21 we would swap around our drivers licenses amongst ourselves before entering a bar and showing them to the bouncer. We didn't all look alike, and we have a variety of weights, hair colors, and skin colors. We'd always get in without a problem then all high five each other and give the licenses back to the proper owner. I'm not sure when exactly we stopped doing it but it was amusing for us for a while to "fool" bouncers.
There was a guy on Pawn Stars who was trying to sell Slash's drivers license. He claimed Slash gave it to his ex girlfriend in return for flashing him her breast. He also claimed to use it as ID to drink from 18-21, apparently being successful despite it not being his ID.
Why would you have someone manually looking at badges? That’s what HID readers are for. I have occasionally seen a security guard in addition to a badge reader to make sure that your face matches the badge photo as you pass through a turnstile, but it doesn’t matter what’s on your badge - the “source of truth” photo is loaded from the database onto the guard’s screen.
I once went to a building I had been in before years earlier, but had installed proxycard activated turnstiles. I told the receptionist I didn't have a card but I knew the building well and she walked me to the ID card office where they made me one on the spot with no verification other than to see if I had a driver's license. The card they made me was good for 5 years and got me right through the turnstiles.
The problem of security guards being too relaxed is a consequence of people being too easily inconvinienced. People don't want to wait while security verifies them, and the security doesn't want to waste time verifying people as they don't have enough incentive and receive pushback if they inconvinience anybody.
The solution would be to give incentive to both sides of the interaction; guards should give positive feedback and e.g. a popsicle to the person being verified if the interaction takes too long and the guard should receive a monetary reward when finding false ID:s (there should be a way to limit the abuse of the proposed system).
Just my 2 cents, feedback and ideas appriciated.
Thank god the TSA is not so lax! All that money going into high-tech state of the art security equipment and advanced training really does the difference.
In my personal experience the TSA security critique stems from them super ultra checking middle eastern looking people and doing security theater for everyone else.
Not sure if people are aware of this. I'm not condoning this behavior, just pointing it out.
"Software without tests should be assumed to not work" is true in real life as well. If an external company tried to enter the building periodically and the security guards review included these tests, it would change.
I've always thought this had more to do with change or attention blindess. The guard looks at identical cards so much that they just can't see that something isn't a card.
I think it's also a convenience thing. One of the most common ways for border agents to go on strike (in Europe at least) is to say "We are going to follow the law to the letter on day so and so"
People end up waiting to cross the border for hours on end.
I imagine security guards at a high traffic building have similar leverage and reasons to be lax. When a few hundred or thousand people have to get in through the lobby every morning in the span of 1 hour ... well I think most people would say "You know what, the probability of something bad happening and the consequence if it does is so low that we'd prefer convenience than standing in line for 3 hours to get to work"
I recall Bruce Schneier writing [1] about a friend of his who had a custom ID card made identifying himself as an ambassador from Mars. It supposedly works way more often than it should.
[1] I don't have the citation and search engines aren't helping. I suspect it was in Beyond Fear.
Woz had a Department of Defiance ID that he used to get into all kinds of places. Apparently it's not illegal because it doesn't actually say 'Department of Defense' so it's not a counterfeit ID card.
IANAL, but I think the legal definition of fraud would make that illegal. You're getting something by deception, since you know the person thinks it says Department of Defence.
There is an adage I came up with when working in the IT security consultancy field: 99% of IT security flaws are people, and 99% of that is complacency.
This something that the speaker in the famous "steal everything, kill everyone..." [1] defcon talk refers to as the "jedi wave" and makes similar remarks about. I think it's a great name.
The guards are probably just doing what they’ve been trained and paid to do.
In the US, security guards are paid somewhere between $20,000 and $40,000, annually. I imagine at that pay rate, a typical guard doesn’t have much motivation to do anything more than follow policy and procedure. That is if they even have policy and procedure.
Most of security instruments (guards or metal detectors) are made for shows and to make people feel secure. If you want to break into the building, just bring your friend and arm yourself with an AK-47 and kill the motherfuckers~.
A couple months ago, I forgot my badge at home, but didn't want to go through the hassle of getting a temp badge, so I flashed my driver's license at the guard (which is roughly the same size as my ID badge) and he simply waved me through.
I told my colleagues this, and since then we have a silly game where we try to get in using ridiculous cards. Most recently, we have people who have flashed blood donation cards (a card that acknowledges that you donated blood on so and so date), a credit card and a folded bookmark and successfully gotten into the complex.
While this is a running joke, really goes to show how lax manual security can be (Especially because once you are on my floor, you can easily tailgate your way into my office).
TL;DR Most of our security systems work on implicit trust more than anything else.