• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Security of faxes

Status
Not open for further replies.

Bletchleyite

Veteran Member
Joined
20 Oct 2014
Messages
113,450
Location
"Marston Vale mafia"
Mod note: split from Paddington Off-Peak validity thread

Haven't GWR said they are faxing the barriers to allow valid Off Peak tickets? Clearly hasn't been dome for tickets with restriction code W1. I guess we'll soon find out if the F3s have been sorted...

I still think a forum meet on a week day evening with an assortment of valid Off Peak tickets should be considered.

Faxing? What year is it again? Is a push technology with no confirmation of reading really an adequate way of informing staff of something important on which they must take action? I bet they won't even read it.

Oh, you mean fixing the barriers. Mind you, the above wouldn't surprise me :)
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

TEW

Established Member
Joined
16 May 2008
Messages
6,226
Fax machines are still in widespread use in the rail industry.
 

Busaholic

Veteran Member
Joined
7 Jun 2014
Messages
14,671
Faxing? What year is it again? Is a push technology with no confirmation of reading really an adequate way of informing staff of something important on which they must take action? I bet they won't even read it.

Oh, you mean fixing the barriers. Mind you, the above wouldn't surprise me :)

Off topic, but fax machines are enjoying a comeback in solicitors' offices owing to the insecurity of the internet when customers are giving instructions on transferring funds for the completion of property purchase - if you don't believe me, google it. Hundreds of thousands of pounds have been fraudently transferred on occasion.
 

richw

Veteran Member
Joined
10 Jun 2010
Messages
11,528
Location
Liskeard
Off topic, but fax machines are enjoying a comeback in solicitors' offices owing to the insecurity of the internet when customers are giving instructions on transferring funds for the completion of property purchase - if you don't believe me, google it. Hundreds of thousands of pounds have been fraudently transferred on occasion.

We're not allowed to email anything containing personal details due to "security" reasons, but can fax anything and everything! (Finance, not solicitors)
 

najaB

Veteran Member
Joined
28 Aug 2011
Messages
33,685
Location
Scotland
We're not allowed to email anything containing personal details due to "security" reasons, but can fax anything and everything! (Finance, not solicitors)
That's because as long as you send it to the correct telephone number it's virtually impossible for someone else to receive it*. It is, however, trivial to fake the sending number.

However faxes have the downside that there is no guarantee that what was sent actually matches what was received. Unlike telexes or signed emails.

*Telco employees excluded.
 
Last edited:

Agent_c

Member
Joined
22 Jan 2015
Messages
934
We're not allowed to email anything containing personal details due to "security" reasons, but can fax anything and everything! (Finance, not solicitors)

Well, a Fax is only sent by one station, and recieved by another. The transmission doesn't rely on a third, fourth, etc station to relay (and trust them not to take a long term copy along the way).

But that said, I doubt its about a rational security concern, but more out of habit and not trusting the new fangled machines (as that security issue can easily be overcome).
 

miami

Established Member
Joined
3 Oct 2015
Messages
3,305
Fax machines don't tend to offer much in the way of security. Compare with sending an email and encrypting it with the recipient's GPG key (and signing with yours)
 

cjmillsnun

Established Member
Joined
13 Feb 2011
Messages
3,275
A fax machine is less secure in every relevant way.

Than email? Unless the email is encrypted it really isn't.

Anyone, anywhere on the internet can potentially intercept the packets which will likely be plain text.

Security wise, an unencrypted email (99.99% of them) and a fax are on a par.
 

Agent_c

Member
Joined
22 Jan 2015
Messages
934
Than email? Unless the email is encrypted it really isn't.

Anyone, anywhere on the internet can potentially intercept the packets which will likely be plain text.

Security wise, an unencrypted email (99.99% of them) and a fax are on a par.

A fax though can be reconstructed through a phone tap.... Before Assange was known for wiki leaks, the Australian Federal Police developed a one-way modem that could reconstruct what a user on a dialup terminal connection was doing based on a taped recording of the phone line at the time, and used that to lock him away... Fax works on the same principles Dial up.

Whilst it is very tangential to what we should be discussing, the point is a fax transmission is essentially in the clear, the tricky part is catching it when it happens.
 

miami

Established Member
Joined
3 Oct 2015
Messages
3,305
Than email? Unless the email is encrypted it really isn't.

Anyone, anywhere on the internet can potentially intercept the packets which will likely be plain text.

Security wise, an unencrypted email (99.99% of them) and a fax are on a par.

I'm currently communicating with railforums.co.uk via unencrypted http. Can you intercept it? The ISP that is providing my VPN exit point can, as can the people running the LONAP Peering LAN AS (coreix) and NIMBUS hosting who run AS21396.

BGP isn't exactly the most secure protocol so you could end up with Pakistan/Youtube situation where traffic is hijacked, but my home ISP is hardly going to believe my BGP adverts, so to say "Anyone, anywhere on the internet" is a rather large exaggeration.
 

DarloRich

Veteran Member
Joined
12 Oct 2010
Messages
32,920
Location
Fenny Stratford
Off topic, but fax machines are enjoying a comeback in solicitors' offices owing to the insecurity of the internet when customers are giving instructions on transferring funds for the completion of property purchase - if you don't believe me, google it. Hundreds of thousands of pounds have been fraudently transferred on occasion.

The fax never really left the solicitors office. Many mortgage companies will only accept a certificate of title via that medium. I have never understood why a pdf couldn't be used
 

edwin_m

Veteran Member
Joined
21 Apr 2013
Messages
28,668
Location
Nottingham
Due to the poor quality of a fax it must be horribly easy to forge something by cutting and pasting, of either the electronic or the traditional variety.
 

dcsprior

Member
Joined
28 Aug 2012
Messages
862
Location
Edinburgh (Fri-Mon) & London (Tue-Thu)
That's because as long as you send it to the correct telephone number it's virtually impossible for someone else to receive it*. It is, however, trivial to fake the sending number.

[SNIP]

*Telco employees excluded.

Criminals could contact the telco pretending to be the intended recipient and claim a line fault, then ask for the line to be diverted to an alternative number.

Someone I know was very nearly robbed using a variant on this scam (it involved a mobile number used for SMS delivery of one-time passcodes rather than a fixed line used for a fax machine) but thankfully their bank spotted and stopped the suspicious activity.

Most email is encrypted in transit these days - major providers (e.g. Google, Microsoft) use SSL/TLS rather than transmitting in plain text.

Good!

I expect that these days that for a huge proportion of email sent from a human being to a human being, both endpoints are either one of the 6 largest webmail providers, or the 4 most popular suppliers of corporate email software. If 10 companies do account for 90% of human to human email traffic (i.e. if my guess is correct) you'd think it'd be easy to ensure everything between them was encypted and signed, and that the user could see that this was the case.
 

Busaholic

Veteran Member
Joined
7 Jun 2014
Messages
14,671
The theoretical security of the fax machine versus email is not the issue - it is the practical situation where a solicitor's office emails their client to ask for the account number and sort code where proceeds of a property sale should be sent - apparently there is a way whereby some sort of scanner can intercept these and the scammer gets the money transferred to their account. With a fax there and back this type of 'random' attack cannot happen. Of course, if the transfer could not be made into an account other than in the name of the legitimate person, then it would be highly improbable that this type of fraud could be viable. It's the usual thing, cut corners and wait for the problems to mount - see City of London Police (lead fraud investigators in this country) and their views on contactless bank cards, driving a coach and horses through the carefully-constructed PIN system.
 

dcsprior

Member
Joined
28 Aug 2012
Messages
862
Location
Edinburgh (Fri-Mon) & London (Tue-Thu)
The theoretical security of the fax machine versus email is not the issue - it is the practical situation where a solicitor's office emails their client to ask for the account number and sort code where proceeds of a property sale should be sent - apparently there is a way whereby some sort of scanner can intercept these and the scammer gets the money transferred to their account. With a fax there and back this type of 'random' attack cannot happen.

So in other words, intercepting / spoofing a fax is perfectly possible, but has a slightly higher cost (in terms of the criminals time) so the return is higher intercepting email than fax.

If most/all email were encrypted from end to end, then intercepting / spoofing email would have a far far far higher cost than fax, and the return would be a lot higher for fax fraud than email.

This is analogous to the fact that there was an increase in cheque fraud and customer not present card fraud, following the introduction of chip & pin - both were already insecure, but the return was higher cloning magstripe cards until that avenue closed.

Similarly, if all financial traffic currently carried by email were to switch back to fax, then the return would increase even though the cost stayed the same, making it worthwhile to criminals to try and intercept/spoof.
 

Johnuk123

Established Member
Joined
19 Mar 2012
Messages
2,800
The Prison service still uses fax on a daily basis to send documents from prison to prison and HQ.
 

Tetchytyke

Veteran Member
Joined
12 Sep 2013
Messages
17,582
Location
Isle of Man
Faxes were often attacked when it was worthwhile to do so. There were countless premium rate phoneline scams, as well as other forms of spoofing, in the 80s and 90s.

Any "security" from a fax now rests solely in the fact they're not common anymore.
 

najaB

Veteran Member
Joined
28 Aug 2011
Messages
33,685
Location
Scotland
Criminals could contact the telco pretending to be the intended recipient and claim a line fault, then ask for the line to be diverted to an alternative number.
They can, but that is a fault of the Telco not performing adequate security checks rather than in inherent flaw in the fax as a transmission medium. Call diversion scamming is surprisingly common, most Telcos will require more than just a random phone call request to set it up e.g. security phrases, quoting full account numbers, etc.
 

miami

Established Member
Joined
3 Oct 2015
Messages
3,305
Could someone please explain how you can intercept an email without actually working for an ISP?
 

dcsprior

Member
Joined
28 Aug 2012
Messages
862
Location
Edinburgh (Fri-Mon) & London (Tue-Thu)
They can, but that is a fault of the Telco not performing adequate security checks rather than in inherent flaw in the fax as a transmission medium. Call diversion scamming is surprisingly common, most Telcos will require more than just a random phone call request to set it up e.g. security phrases, quoting full account numbers, etc.

Yeah, but a secure handshake would remove this vulnerability.

Fax machinesbasically assume the transmission medium is 100% secure. It isn't (though it requires some effort to compromise) and if someone compromises the lower levels, the higher levels (i.e. the protocols the fax machines use) offer little or no protection.

With email, you should assume the underlying transmission medium is 0% secure. If all email programs/providers dis, then there'd be no security issues. In fact, fax machines should make that assumption too.
 

najaB

Veteran Member
Joined
28 Aug 2011
Messages
33,685
Location
Scotland
Could someone please explain how you can intercept an email without actually working for an ISP?
DNS poisoning is one way - publish a false MX record. More commonly, malware that redirects connection attempts to the bad guys' network.
 

PermitToTravel

Established Member
Joined
21 Dec 2011
Messages
3,042
Location
Groningen
If you've enough trust on the network to "publish" a false MX record (i.e. you can MiTM IP, so presumably are advertising a BGP prefix containing the victim's choice of DNS server), you could just intercept connections to the real MTA. It rather involved being on the other side of this airtight hatchway

If fax machines were regularly used for anything that people are trying to intercept, there would very quickly be plenty of malware written to run on them.
 
Status
Not open for further replies.

Top