Want to get paid for a vulnerability similar to this one?
Contact us at: firstname.lastname@example.org
I first saw this, appropriately enough, on Improbable Research. It’s appropriate, because, when you see it, first it makes you laugh. Then it makes you think.
This guy has created a paper safe. Yeah, you got that right. A safe, made out of paper. No, not special paper: plain, ordinary paper, the kind you have in your recycling bin. He’s even posted a video on YouTube showing how it works.
Right, so everyone’s going to have a good laugh, yes? Paper isn’t going to provide any protection, right? It’s a useless oddity, of interest only to those with an interest in origami, and more free time on their hands than any security professional is likely to get.
Except, then you start thinking about it (if you are any kind of security pro.) First off, it’s a nice illustration of at least one form of combination lock. And then you realize that the lock is going to be useless unless it’s obscured. So that brings up the topic of maybe security-by-obscurity does have a function sometimes.
Then you start thinking that maybe it isn’t great as a preventive control, but it sure works as a detective control. Yeah, it’s easy to smash and get out whatever was in there. But it’ll sure be obvious if you do.
So that brings up different types of controls, and the reasons you might want different controls in different situations, and whether some perfectly adequate controls may be a) overkill, or b) useless under certain conditions.
It’s not just a cute toy. It’s pretty educational, too. No, I’m not going to keep my money in it. But it makes you think …