Yankees announce improved security and entrance measures for fans (Crain's) — Yankee Stadium visitors soon will be able to avoid long security lines by registering their fingerprints with a biometric identity service used at 12 U.S. airports.
In another deployment the St. Louis Cardinals (baseball's second-most successful franchise in history) have installed iris biometrics for player and staff access control in more secure locations.
Showing posts with label physical. Show all posts
Showing posts with label physical. Show all posts
Thursday, August 6, 2015
Thursday, June 25, 2015
The line between Security and IT is getting blurrier
Bridging the gap between physical and logical access (Security Info Watch)
With the push by many end-users to migrate their physical access control systems to the IT network in recent years has also come an increased demand for solutions that can streamline both physical and logical access in a way that is less burdensome on workers.Read the whole thing.
Monday, October 6, 2014
Friday, December 28, 2012
Illinois: Biometrics enable pay-as-you-go gym
Futuristic 24-Hour Gym Opens in Bucktown (Racked)
Sounds fancy, and with fancy comes a fancy price tag, right? Not really--because there basically isn't any staff the charge is $3.75 per visit after a base monthly charge of $19 and a $99 technology/enrollment fee. Classes (with instructors, not supervisors) start January 1.We're going to be seeing a lot more of this.
Thursday, June 28, 2012
A case for Iris as the Killer Modality
Jeff Carter has made his TEDxEast talk, "Your Eye Will Unlock The World," available online (YouTube).
He's also on Twitter at @EyeLock_1.
He's also on Twitter at @EyeLock_1.
Monday, May 7, 2012
Security & Trust
I love it when InfoSec Island gets all philosophical about security.
Today's example is the excellent Understanding Trust by Kevin W. Wall.
For an earlier example, see: Human Security is Weaker than IT Security*
While Infosec Island (obviously) concerns itself with Information Security ("logical access control" for ID management types) much of their analysis can be applied to the world of physical security as well.
*Human Security is Weaker than IT Security inspired this post: The Con is Mightier than the Hack
Today's example is the excellent Understanding Trust by Kevin W. Wall.
At its core, information security is largely about the two goals of “ensuring trust” and “managing risk”. We may deal with managing risk some other time, but today I want to focus on ensuring trust.Read the whole thing.
In order to ensure trust, we first must understand not only what it is, but what its properties are...
For an earlier example, see: Human Security is Weaker than IT Security*
While Infosec Island (obviously) concerns itself with Information Security ("logical access control" for ID management types) much of their analysis can be applied to the world of physical security as well.
*Human Security is Weaker than IT Security inspired this post: The Con is Mightier than the Hack
Wednesday, April 18, 2012
Securing Corporate Data in the Cloud: Biometric Logical and Physical Access Control
How to make information stored in the cloud robustly safe (The Guardian)
Most articles like this mention biometrics only in the context of physical access control at the data center, which is important. You don't hear as much about biometrics for controlling access to data stored in the cloud, though, and that's too bad because biometrics for logical access control could make the cloud a lot safer for businesses and their customers.
At a data center, physical access control prevents this (access to places)...
Logical access control is for this (access to information)...
...and tricking out data centers like Fort Knox, along with other logistical challenges ensures that there are a lot more of the latter than the former.
In networked logical access control solutions, the biometric sensor hardware is a part of the security. In the standard Username/Password regime, the hardware used, the keyboard, offers no additional security. With username/password authentication, a hacker needs only a keyboard to fill in the proper fields and she gains access to the network. If that username/password is a superuser or administrator credential, there's may be some turnover in the CTO function.
Biometric authentication is very different animal because with biometrics, the hardware layer does provide extra security. If the hacker steals a biometric or unencrypted biometric template (a long character string), she can't just type it in even if she finds the place in the programming that handles the template. The template resulting from a verification attempt is like a single use password created during the interaction of a physical object (body part) with certain known sensor.
For organizations using cloud services, requiring biometric authentication to authorize access to any database storing usernames/passwords should dramatically decrease the risk of high profile data breaches or other damaging hacks.
But even if every human account used biometrics for logical access control, some version of username/password verification will be around for a long, long time because username/password is a cheap, well-understood, flexible technology that supports certain access control models that biometrics does not. For one thing, people aren't the only things that claim an identity before accessing IT systems — computers do it, too, and they don't have biometrics.
The challenge that system designers now face is to identify where using Username/Password is too dangerous, and where biometrics can be used to reduce risk to an acceptable level. This requires identifying everything currently authenticated with a username/password and a determining which of these things are more efficiently protected using biometric authentication, then implementing the change. This is far easier said than done.
Requiring biometric verification of all human Administrator logins would be a good start, though. There aren't (or shouldn't be) that many of them. They are tech savvy, so they should be able to adapt to the new security environment quickly. They should have an understanding of why the extra step is worth the effort. It's their responsibility to keep the keys of the kingdom and they're the ones on the hot seat when the CEO is out apologizing to all and sundry following a data breach.
Most articles like this mention biometrics only in the context of physical access control at the data center, which is important. You don't hear as much about biometrics for controlling access to data stored in the cloud, though, and that's too bad because biometrics for logical access control could make the cloud a lot safer for businesses and their customers.
At a data center, physical access control prevents this (access to places)...
![]() |
| Image: Copyright Paramount |
Logical access control is for this (access to information)...
...and tricking out data centers like Fort Knox, along with other logistical challenges ensures that there are a lot more of the latter than the former.
In networked logical access control solutions, the biometric sensor hardware is a part of the security. In the standard Username/Password regime, the hardware used, the keyboard, offers no additional security. With username/password authentication, a hacker needs only a keyboard to fill in the proper fields and she gains access to the network. If that username/password is a superuser or administrator credential, there's may be some turnover in the CTO function.
Biometric authentication is very different animal because with biometrics, the hardware layer does provide extra security. If the hacker steals a biometric or unencrypted biometric template (a long character string), she can't just type it in even if she finds the place in the programming that handles the template. The template resulting from a verification attempt is like a single use password created during the interaction of a physical object (body part) with certain known sensor.
For organizations using cloud services, requiring biometric authentication to authorize access to any database storing usernames/passwords should dramatically decrease the risk of high profile data breaches or other damaging hacks.
But even if every human account used biometrics for logical access control, some version of username/password verification will be around for a long, long time because username/password is a cheap, well-understood, flexible technology that supports certain access control models that biometrics does not. For one thing, people aren't the only things that claim an identity before accessing IT systems — computers do it, too, and they don't have biometrics.
The challenge that system designers now face is to identify where using Username/Password is too dangerous, and where biometrics can be used to reduce risk to an acceptable level. This requires identifying everything currently authenticated with a username/password and a determining which of these things are more efficiently protected using biometric authentication, then implementing the change. This is far easier said than done.
Requiring biometric verification of all human Administrator logins would be a good start, though. There aren't (or shouldn't be) that many of them. They are tech savvy, so they should be able to adapt to the new security environment quickly. They should have an understanding of why the extra step is worth the effort. It's their responsibility to keep the keys of the kingdom and they're the ones on the hot seat when the CEO is out apologizing to all and sundry following a data breach.
Labels:
Big Data,
biometrics,
data center,
hack,
logical,
physical,
security
Monday, March 26, 2012
Security At Visa's Top Secret Data Center
Prisons are easier to enter than Visa's top-secret Operations Center (WLTX - Columbia, SC)
"Physical security is the foundation where you start," says John Thielens, chief security officer of Axway, a business-software vendor. "If you can afford it, build a data center. The big guys build their own."Security is provided in layers. This article illustrates it.
...
Once inside, visitors encounter a "mantrap" portal, which requires a badge and biometric image of the right index finger to gain access to the data center. The digital image is necessary to pass through a phalanx of shatter-resistant glass doors.
Wednesday, February 8, 2012
New Mexico: Access to Holloman Air Force Base Requires a Fingerprint
New DBIDS requirements ensure safety, ease of access (Holloman Air Force Base)
After a brief hiatus to upgrade the software on the 49th Security Forces Defense Biometric Identification System, as of Feb. 1 hand-held scanners are being used again at all three gates at Holloman AFB.
Using barcode technology and fingerprints to verify the access authorization of everyone entering the installation, DBIDS is the latest step in helping security forces here improve safety and security for the Holloman community and its resources.
Wednesday, October 26, 2011
Adoption: Biometrics for Physical Access Control
Government drives match-on-card, new commercial uses emerge (SecureIDNews)
h/t @m2sys
Governments across the globe are driving the use of biometrics, says Dave Adams, senior product marketing manager for Identity and Access Management at HID Global. India, South Africa and Brazil are looking at fingerprint technology to secure facilities. Iris is also on the radar, he adds, but not nearly as prevalent to date. Fingerprint continues to gain in popularity because of its improved accuracy and lower cost. In the past, Adams explains, biometric technology had issues. “The reality hit that you would be holding up people at the front door with false accepts and false rejects,” he says. “The technology has improved dramatically over the past decade.” Many countries are looking at what the U.S. has done with FIPS 201, trying to create a similar specification for use by their government employees, Adams says.This long piece is chock full of biometrics for physical access control standards, applications and methods.
h/t @m2sys
Saturday, October 1, 2011
Insight into Google's Ideas about Security
Googling from the inside out (Smart-Grid.TMCNet.com)
The article is about Google's Pryor, Oklahoma data center. A large section, however, is devoted to Google's and the center's approach to security.
The relevant paragraph is the longest one. It begins:
The article is about Google's Pryor, Oklahoma data center. A large section, however, is devoted to Google's and the center's approach to security.
The relevant paragraph is the longest one. It begins:
"We take security and privacy very seriously which is why our facilities are not something we have regular tours through," he said. "This is why we have the kind of fencing which you might see at a medium-security prison, because if that trust (in Google) goes away, it would be very difficult for us to get it back." "Besides the fencing and the gate, we have an extensive security system," Wooten said. "Of course, we have security cameras, highly controlled badge access in biometrics to the facility and specific parts of the facility which are more sensitive, iris scans, fingerprint scans, and even restricted access to other 'Googlers' -- only the people who are authorized to be in a certain location have access. Even people from other Google data centers, there are five in the U.S., don't have clearance to our center -- security is that tight."
Thursday, September 22, 2011
The Securest Home in America
You could buy the fortress that some consider the most secure home in America for just $5.9 million (MetroWest Daily)
Click here for photos of the Poland safe house mentioned in the article.
The home has extensive surveillance, and biometric scanners for all entry points. The home also has two secret panic rooms to escape from intruders, and two “safe cores” that are invisible and fully isolated from the rest of the house. These safe cores provide a retreat during a potential nuclear or biological attack.There's a photo of the Los Angeles mansion at the link.
Click here for photos of the Poland safe house mentioned in the article.
Tuesday, August 2, 2011
Network Security: Don't Forget Physical Access Control
Locking Down Physical Access Is Key (or Badge) to Security (IT Business Edge)
So much of IT’s focus on security is devoted to encrypting data and locking down the perimeter that it’s easy to forget that if somebody can just walk into your server room, they can do enough damage to your network to make the Sasser outbreak look like a forgotten password help desk ticket.Good piece with links to other articles and resources.
Monday, April 18, 2011
Four Factor Authentication
The fourth factor is location (SCMagazineUK.com)
This is one of those articles that is a grab-bag of interesting identity management stuff.
If the fourth factor is location, we're obviously talking logical access control since with physical access control, location isn't in doubt.
For physical access control, a fourth factor might be time, i.e. your credentials only open the door at certain times of the day.
But time can also be a part of the 4th factor in logical verification if, for instance, your bank wanted to know about it if you use your bank card in the Enid, Oklahoma Wal-Mart fifteen minutes before "you" use the same card in St. Petersburg, Russia. Since you cant get from Enid to St. Petersburg in 15 minutes, there's a chance something is amiss.
As they say, read the whole thing.
See also: Biometrics in Emergencies which also touches upon the time factor in physical access control systems.
This is one of those articles that is a grab-bag of interesting identity management stuff.
If the fourth factor is location, we're obviously talking logical access control since with physical access control, location isn't in doubt.
For physical access control, a fourth factor might be time, i.e. your credentials only open the door at certain times of the day.
But time can also be a part of the 4th factor in logical verification if, for instance, your bank wanted to know about it if you use your bank card in the Enid, Oklahoma Wal-Mart fifteen minutes before "you" use the same card in St. Petersburg, Russia. Since you cant get from Enid to St. Petersburg in 15 minutes, there's a chance something is amiss.
As they say, read the whole thing.
See also: Biometrics in Emergencies which also touches upon the time factor in physical access control systems.
Monday, January 31, 2011
Access control critical for security
Access control critical for security, and other things (ITWeb S. Africa)
Experts in the field of biometric-based security systems believe that knowing the movements of people within the company or business is, especially from a security perspective, of paramount importance to decision makers.Understanding how employees act within and move about an organizations has value beyond the security function.
Wednesday, December 8, 2010
Physical access control more popular than logical access control
Majority of organisations using biometrics are leaving logical IT access protection at the door (SecurityPark.co.uk)
Biometric ID management techniques do yield significant ROI for logical access control -- passwords don't reset themselves and the people you call get paid -- but it's more difficult to compute and is likely to make itself apparent over the longer term.
According to new research from Siemens IT Solutions and Services, only 18% of organisations with biometric measures currently in place are using them for logical access control – vital to securing IT equipment and data files.The huge uptick in the popularity of time-and-attendance access control systems, with their clean and easy calculations of ROI (return on investment) may account for some of this discrepancy.
Despite acknowledging the need for greater IT security in a climate of cyber crime and terrorism, biometrics professionals are opting for physical access control to safeguard rooms or buildings. This presents IT security threats to sensitive data within organisations and potential mobile IT security weaknesses.
Biometric ID management techniques do yield significant ROI for logical access control -- passwords don't reset themselves and the people you call get paid -- but it's more difficult to compute and is likely to make itself apparent over the longer term.
Subscribe to:
Posts (Atom)

