Stupidity of guessable Access Codes

| No Comments | No TrackBacks
During my trip through Australia I've discovered different security and access control systems of hostels all over the country. Unfortunately, most of them are not very secure and as a proof, I'd like to show you some of the access codes of my last hostel.

Hostel_AccessCode.JPG

Actually, these access codes are retrieved from the doors of my rooms "40" and "35" where I have slept in. "CX90" and "CI15" are the id from the floor where the rooms are located, whereas the last part is set to the last room on the floor "48" or "38". Some of my friends have slept in room 32 and got room code "C15Z32". 

As you see, the codes are not very hard to guess and offer no security for the backpackers sleeping in there. As there was no locker available, you just could hope everybody was so friendly not to steal anything while you've been out for a few drinks.

Therefore, if you have access codes in place, they should never be guessable and of course, they should be changed from time to time, so that, in case somebody publishes the codes or gets access to these codes, your company still remains secure. 

No TrackBacks

TrackBack URL: http://www.securitypitfalls.org/admin/mt-tb.cgi/93

Leave a comment

User ranking

User     Reported Pitfalls
Flo4
Norb4
Berni2
Sup2
Ali1
Churchy1
JG1
Nuuz1
Trixi1
vmorbit1

Idea behind SecurityPitfalls.org

SecurityPitfalls is an educational, supportive and fun project and depends strongly on the community that drives this project. For further information visit the article What's the basic idea behind SecurityPitfalls.org

About this Entry

This page contains a single entry by Tom published on December 1, 2009 12:32 PM.

Would you trust this ATM? was the previous entry in this blog.

Security in Hostels is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Categories

Send in your photos and stories

SecurityPitfalls.org is a community project where we work together and collect situations where security fails, primarily for educational purpose, as source for discussions and presentations and fun. Send your photos (digi cam/handy), stories or movies to incoming {at} securitypitfalls.org and we will post your experiences you want to share with other people.