News: 1715077807

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Physical security biz exposes 1.2M files via unprotected database

(2024/05/07)


Exclusive A UK-based physical security business let its guard down, exposing nearly 1.3 million documents via a public-facing database, according to an infosec researcher.

A researcher [1]says they stumbled upon a trove of data belonging to Amberstone Security, which included thousands of pictures of its guards as well as pictures of individuals suspected of offenses including shoplifting.

In total, 1,274,086 documents were exposed to the internet via a misconfigured database for an unknown length of time, we're told. It's unclear if the data had ever been accessed by anyone with malicious intent.

[2]

Amberstone Security offers surveillance, access control, and merchandise-protection products and services, as well as guards on 24-hour duty to customers.

[3]

[4]

Among the exposed data, which dates back to 2017, was a folder containing 99,151 snapshots of guards checking in for their shifts, either by using a picture of themselves, their ID cards, or both. The pictures taken of the ID cards displayed basic information such as their name, headshot, and the card's expiry date. In rare cases, it showed their signature too.

The ID cards were also issued by the Security Industry Authority (SIA), the UK's regulator for the private security industry. The cards do not have any biometric technology built into them and are basic, plastic ID cards that hypothetically could be fairly easily duped and abused.

[5]

Speaking to The Register , researcher Jeremiah Fowler, claimed the SIA told him there are plans to introduce biometry to the cards in the near future. However, there is no specific date for this.

"The exposure of SIA identification documents could pose a serious potential threat to public safety, personal privacy, and the integrity of security operations if misused by unauthorized individuals," said Fowler.

"One hypothetical example of a risk scenario would be if criminals used the exposed information such as the guard's names, photographs, and license numbers to impersonate security personnel or gain unauthorized access to a secure facility for criminal purposes. This could potentially lead to a [6]physical security breach , theft, vandalism, or – as a worst-case scenario – acts of terrorism."

[7]

Exposing a database in any case would present obvious privacy risks, and these are amplified if the exposed data ties an individual to a suspected crime, which was the case in this incident.

Fowler says the documents found in the exposed database showed images of suspected offenders either seemingly caught in the act via CCTV or photographed by security personnel afterward. Many images clearly depicted the suspects and were captioned with information such as their name, date of birth, and nature of their alleged offense.

In some cases, detailed descriptions of how a suspect operates were found, said Fowler. One man and his associates were known to frequent the Lakeside and Stratford shopping centers in the south east of England, for example, and apparently had a particular penchant for high-value men's suits.

The description contained details about how suspected offenders got away with the thefts, mentioning that they later return to the store and target young staff to complete a confusing process to obtain a cash refund on the stolen goods.

Similarly, spreadsheets were also filled with information about offenses, how they were committed, and whether violence was used or not.

[8]UK's Investigatory Powers Bill to become law despite tech world opposition

[9]Exposed: Chinese smartphone farms that run thousands of barebones mobes to do crime

[10]Amazon Ring sounds death knell for surveillance as a service

[11]UK policing minister urges doubling down on face-scanning tech

Swift response

A day after being alerted to the exposed database, Amberstone Security revoked public access to the database and informed Fowler that the blunder may have been caused by a third party.

"Thank you for bringing this to our attention, this is deeply concerning. I am investigating this with the supplier who developed and hosts the platform," a company rep told the researcher. "Please rest assured that we take data security seriously, and this will be investigated thoroughly."

The Register contacted Amberstone for a response and a spokesperson for parent company Argenbright Security Europe said: "Amberstone were made aware of a server configuration issue and immediately contained any risks. We have acted accordingly and in line with our regulatory obligations."

The identity of the third-party contractor was not specified by Amberstone Security. ®

Get our [12]Tech Resources



[1] https://www.websiteplanet.com/news/amberstone-breach-report/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZjpQHKCnUe@-XY@VV8jA@QAAAIs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjpQHKCnUe@-XY@VV8jA@QAAAIs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZjpQHKCnUe@-XY@VV8jA@QAAAIs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjpQHKCnUe@-XY@VV8jA@QAAAIs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2022/07/07/lock_down_your_piss_corridor/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZjpQHKCnUe@-XY@VV8jA@QAAAIs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2024/04/26/investigatory_powers_bill/

[9] https://www.theregister.com/2024/03/21/china_smartphone_farms/

[10] https://www.theregister.com/2024/01/25/amazon_ring_sounds_death_knell/

[11] https://www.theregister.com/2023/10/31/uk_police_minister_lfr/

[12] https://whitepapers.theregister.com/



Only now?

Mike 137

" I am investigating this with the supplier who developed and hosts the platform "

Yet another example of what I defined a couple of decades back as 'fire and forget management'. At least in the UK, the law actually requires the first party to take responsibility for third party data breaches, so it amazes me that said first parties never seem to check the security of their subcontractors' systems or activities until it's too late. How many businesses get their online offerings pen tested? Practically none in my experience.

Re: Only now? - 'Fire and Forget'

Eclectic Man

I went to a presentation by a senior executive just after I joined my last company. He said he liked the idea of 'fire and forget', which he took as something from the Vietnam war, when a missile could be fired and it would find its own way to the target, so the pilot could just forget it. Unfortunately the Western powers lost the Vietnam war, and the most appropriate quotation from that conflict is surely the response of the senior US General when asked to assess the situation after the Viet Minh had taken the last heights surrounding Phnom Penh " We're F**ked". Consternation from the assembled journalists, who wanted something they could print. But the general insisted "We're F**ked. They can kill us any time they want."

I am not a fan of 'fire and forget management.

Re: Only now? - 'Fire and Forget'

General Purpose

>the Viet Minh had taken the last heights surrounding Phnom Penh

The North Vietnames surrounded Cambodia's capital city with American forces in it? Is this about someone else or some other place, one that is surrounded by heights?

Doctor Syntax

I wonder if, when a contractor is working on a building that Amberstone guard, they send along one of their security guards to oversee the job.

Defence in depth

Brewster's Angle Grinder

"Thank you for bringing this to our attention...I am investigating who I can transfer blame for this to."

The scary thing is not that this was exposed to the internet (although that's bad enough) but that once you are inside the system, there is zero control or auditing. Anybody with the password can, apparently, see it all. But the trousers have been pulled up so the shit remains hidden.

perkele

Most physical guarding is a sham with "minimum wage SIA monkeys" doing the bare minimum. A facade.

re: Security guarding

Eclectic Man

One of my friends was a 'night watchman' for two years. He spent all his time reading the Financial Times, and now runs a business that owns at least three pubs.

Another story about physical guarding: BT has a lot of large old buildings that used to house the enormous Strowger telephone exchanges. Anyway, BT moved out of quite a few due to the economies of electronics, but robbers used to try to steal stuff from them (copper piping a favourite, whether connected to the mains water supply or not). So BT had lots of security guards who would try to chase the miscreants away, but often failed. So BT hired some retired Gurkha soldiers as guards. Their policy was to let the thieves enter, and when they were just about to start stealing something, creep up silently behind them and shout "BOO!" very loudly into their ear. Scared the shit out of them - they never came back.

Bouncers get bounced

xyz

It's amazing that this sort of thing still happens. More details please.. Was it some Access job in a public folder under a web site root or what? Or just the normal clear text username=admin, password = 123456789 thing. Or both?

as well as pictures of individuals suspected of offenses including shoplifting

heyrick

Suspected, huh?

Suspected ?

And are the "suspected" aware that their photos have not only been retained by this outfit, but now leaked?

sitta_europea

Many years ago I used to provide a service to disinfect virus-ridden computers.

My personal best for a single computer in a single company was just over 1,000 viruses.

At the offices of this company, when I discovered the state of it I told the computer's user (the MD's secretary) that it would take a while to get rid of all the viruses, and, as there would be a lot of waiting around for scans, it would be easiest if I took it back to my office to do it there. It wasn't usable as it was anyway. She said fine, so I took it and started work.

Some hours later an irate Managing Director was on the 'phone saying I must take the computer back to their offices immediately.

I took the lack of any explanation to mean that there was something on there that the MD didn't want me to see.

I took it back, still riddled with viruses, and I never heard from them again.

It's (still) a physical security company in Sutton-in-Ashfield, Nottinghamshire.

They still advertise "First Class Security...", which kinda sums it all up for me.

Struggling nowadays to find *anything* that isn't built on lies.

Luckily Britain's banks have been working hard for years to reduce bank robberies.

Tron

By closing all the branches.

Re: Luckily Britain's banks have been working hard for years to reduce bank robberies.

ColinPa

In yesterday's paper was a comment, about reducing the number of train which get cancelled - we'll remove them from the time table - so there are fewer trains - so the absolute number will decrease.

We did the bare minimum folks, yay us!

Dan 55

"We have acted accordingly and in line with our regulatory obligations."

Committee Rules:
(1) Never arrive on time, or you will be stamped a beginner.
(2) Don't say anything until the meeting is half over; this
stamps you as being wise.
(3) Be as vague as possible; this prevents irritating the
others.
(4) When in doubt, suggest that a subcommittee be appointed.
(5) Be the first to move for adjournment; this will make you
popular -- it's what everyone is waiting for.