Lawyer ⚖️, Historian, Navy vet ✈️, Philly and Penn State sports fanatic 🏈⚾🏀, Dad and Husband. Blogging at the intersection of state power and civil liberties.
Showing posts with label disney. Show all posts
Showing posts with label disney. Show all posts
05 January 2014
04 January 2014
This is probably an important part of the ship
I didn't realize cruise ships (or ships in general) had Voyage Data Recorders, although it's not surprising. This one was mounted above the bridge (it's difficult to tell from the second photo, but this is on the 10th deck). I was surprised that it was more or less accessible, and that the cable to the bridge was exposed.
27 December 2013
26 December 2013
People play Bingo for money. So these wireless devices are secure, right?
Has anyone ever played Bingo with one of these wireless devices? How much do you want to bet that the data is not encrypted, or is otherwise manipulable? To be clear, I did not have the right equipment with me to test these devices--I'm just guessing here.
24 December 2013
Disney's Windows application crashes, exposes data?
While on-board our Disney cruise, we visited an area of the ship where Disney provides kiosks or large touchscreen monitors that display photographs that have been taken of you (or your party). To access the photographs, you swipe your "Key to the World" card. Except when the "PhotoFinder" program crashes (see first image below). And when the card reader program exposes folio numbers (see second image below).
I have no idea if or how the "folio numbers" relate to individual customers or their "Key to the World" cards. I don't know if this data could lead to exposure of customer data, because, although I am curious, I wanted to enjoy my cruise and didn't investigate further. But it does demonstrate that data leaks can happen when programs crash.
One other thing: the touchscreen displays appear to be covered at the bottom by an inch or so--presumably so that your fingers don't activate the "Start" menu. But this is just a guess (and, it doesn't work!).
Oh, and in case you're wondering: I re-started PhotoFinder. :-)
21 September 2013
Dear Disney, why did you approve this product?
Using your most prominent character to show contempt for other people's opinions doesn't seem to fit the values that Disney ought to be endorsing.
17 April 2012
Vacations and social media opsec
I just returned from five days of vacation in Florida. Chances are that (unless you follow me on Foursquare and scrutinize my check-ins) you probably didn't know I was gone. We posted no pictures of our vacation activities, didn't make any comments or posts related to what we were doing. One exception that I noted above was Foursquare, where I did check in partly to record our trail of activities and also because I have less followers there and was less concerned about word getting out.
Sites like Please Rob Me (if perhaps a bit over-hyped) highlight the concerns about posting your activities on social media. Especially important is when you're away from home for an extended period of time. Thus, this was a deliberate strategy that Tracy and I followed explicitly for this purpose.
But this is probably not enough. I post a lot on both Twitter and Facebook and if I suddenly disappeared for a while, someone might take notice of that, too. So, step two: Using Buffer (or some other similar application), each night I scheduled a series of tweets and posts spread out during the next day on subjects that I usually talk about. From a third party perspective, things ought to seem just plain ordinary. So when you thought I was tweeting about some infosec article, I was probably riding a roller coaster. :-)
The idea here wasn't or isn't to trick anyone or orchestrate some elaborate deception campaign, just to be careful about what you're posting in similar circumstances; and follow that up with the same sort of content and material that people already expect of you.
Now that we're home again, you can expect to see pictures from the vacation in the near future. I also have some notes about some of our interesting experiences over the last week to flesh out into blog posts.
Now, I need some sleep...
Sites like Please Rob Me (if perhaps a bit over-hyped) highlight the concerns about posting your activities on social media. Especially important is when you're away from home for an extended period of time. Thus, this was a deliberate strategy that Tracy and I followed explicitly for this purpose.
But this is probably not enough. I post a lot on both Twitter and Facebook and if I suddenly disappeared for a while, someone might take notice of that, too. So, step two: Using Buffer (or some other similar application), each night I scheduled a series of tweets and posts spread out during the next day on subjects that I usually talk about. From a third party perspective, things ought to seem just plain ordinary. So when you thought I was tweeting about some infosec article, I was probably riding a roller coaster. :-)
The idea here wasn't or isn't to trick anyone or orchestrate some elaborate deception campaign, just to be careful about what you're posting in similar circumstances; and follow that up with the same sort of content and material that people already expect of you.
Now that we're home again, you can expect to see pictures from the vacation in the near future. I also have some notes about some of our interesting experiences over the last week to flesh out into blog posts.
Now, I need some sleep...
Subscribe to:
Posts (Atom)



