<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: What the Designers of Bank Vaults Should Learn from the Field of Computer Security</title>
	<atom:link href="http://pragmattica.wordpress.com/2009/03/19/what-the-designers-of-bank-vaults-should-learn-from-the-field-of-computer-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://pragmattica.wordpress.com/2009/03/19/what-the-designers-of-bank-vaults-should-learn-from-the-field-of-computer-security/</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Thu, 05 Nov 2009 14:43:13 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Anonymous</title>
		<link>http://pragmattica.wordpress.com/2009/03/19/what-the-designers-of-bank-vaults-should-learn-from-the-field-of-computer-security/#comment-168</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Sun, 14 Jun 2009 11:47:27 +0000</pubDate>
		<guid isPermaLink="false">http://pragmattica.wordpress.com/?p=31#comment-168</guid>
		<description>This biggest vulnerability with this safe is if thieves find the code.  The safe in the diamond heist had a lock with 100^4 combinations, yet they got video footage of the code being entered.  If the thieves got that on your idea there would be no other security.  with a security by obscurity method there would at least be other safeguards in place.</description>
		<content:encoded><![CDATA[<p>This biggest vulnerability with this safe is if thieves find the code.  The safe in the diamond heist had a lock with 100^4 combinations, yet they got video footage of the code being entered.  If the thieves got that on your idea there would be no other security.  with a security by obscurity method there would at least be other safeguards in place.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://pragmattica.wordpress.com/2009/03/19/what-the-designers-of-bank-vaults-should-learn-from-the-field-of-computer-security/#comment-124</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Fri, 24 Apr 2009 00:26:03 +0000</pubDate>
		<guid isPermaLink="false">http://pragmattica.wordpress.com/?p=31#comment-124</guid>
		<description>Nothing is hidden or secret about the way a simple tumbler vault vault works...just like a computer algorithm....the only thing a thief is missing is the correct key/combination. Now you say that keys locks can be &#039;picked&#039; and tumbler locks can be &#039;the equivalent of picking, like with the stethoscope in the movies&#039;, but the same can be said for computer algorithms. Point in case - WEP encryption for wireless routers. hackers learned how to intercept data traveling between host and client and decrypt the password (pick the lock)!</description>
		<content:encoded><![CDATA[<p>Nothing is hidden or secret about the way a simple tumbler vault vault works&#8230;just like a computer algorithm&#8230;.the only thing a thief is missing is the correct key/combination. Now you say that keys locks can be &#8216;picked&#8217; and tumbler locks can be &#8216;the equivalent of picking, like with the stethoscope in the movies&#8217;, but the same can be said for computer algorithms. Point in case &#8211; WEP encryption for wireless routers. hackers learned how to intercept data traveling between host and client and decrypt the password (pick the lock)!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bnsmith</title>
		<link>http://pragmattica.wordpress.com/2009/03/19/what-the-designers-of-bank-vaults-should-learn-from-the-field-of-computer-security/#comment-123</link>
		<dc:creator>bnsmith</dc:creator>
		<pubDate>Thu, 23 Apr 2009 02:10:25 +0000</pubDate>
		<guid isPermaLink="false">http://pragmattica.wordpress.com/?p=31#comment-123</guid>
		<description>I suppose that if a hacker managed to jam the computer or if the computer itself crashed, there would be no alternative but to drill through the wall of the vault. It would be a time consuming and expensive proposition, but still better than the computer security equivalent. If you lose the password for a Truecrypt volume, for example, it might take a billion years for the brute force attack to work!</description>
		<content:encoded><![CDATA[<p>I suppose that if a hacker managed to jam the computer or if the computer itself crashed, there would be no alternative but to drill through the wall of the vault. It would be a time consuming and expensive proposition, but still better than the computer security equivalent. If you lose the password for a Truecrypt volume, for example, it might take a billion years for the brute force attack to work!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jpdemers</title>
		<link>http://pragmattica.wordpress.com/2009/03/19/what-the-designers-of-bank-vaults-should-learn-from-the-field-of-computer-security/#comment-122</link>
		<dc:creator>Jpdemers</dc:creator>
		<pubDate>Wed, 22 Apr 2009 06:54:34 +0000</pubDate>
		<guid isPermaLink="false">http://pragmattica.wordpress.com/?p=31#comment-122</guid>
		<description>Better hope the computer in the vault never fails!

What struck me about the Antwerp Diamond District vault was the idiotic practice of turning off the lights at night, thereby blinding the video surveillance system.</description>
		<content:encoded><![CDATA[<p>Better hope the computer in the vault never fails!</p>
<p>What struck me about the Antwerp Diamond District vault was the idiotic practice of turning off the lights at night, thereby blinding the video surveillance system.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Salil</title>
		<link>http://pragmattica.wordpress.com/2009/03/19/what-the-designers-of-bank-vaults-should-learn-from-the-field-of-computer-security/#comment-120</link>
		<dc:creator>Salil</dc:creator>
		<pubDate>Mon, 06 Apr 2009 19:35:29 +0000</pubDate>
		<guid isPermaLink="false">http://pragmattica.wordpress.com/?p=31#comment-120</guid>
		<description>I have an Infosec background myself, and I&#039;d be more wary of the communications channel you describe as a vulnerability, given the &quot;traditional&quot; dependence on off-the-shelf protocols for that sort of thing. 

Imagine a hacker who can&#039;t break into the safe, but can jam the code up so well with an exploit that he can effectively hold the contents of the safe hostage.</description>
		<content:encoded><![CDATA[<p>I have an Infosec background myself, and I&#8217;d be more wary of the communications channel you describe as a vulnerability, given the &#8220;traditional&#8221; dependence on off-the-shelf protocols for that sort of thing. </p>
<p>Imagine a hacker who can&#8217;t break into the safe, but can jam the code up so well with an exploit that he can effectively hold the contents of the safe hostage.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
