Threat Boundaries and Appropriate Security Claims
SUMMARY
Defines the attacker classes, environmental assumptions, and asset types for which pendulum/cable security provides meaningful protection.
DETAIL
Pendulum/cable security is strongest against opportunistic access in visible, shared, and structurally controlled environments. It can make accidental entry, casual theft, unauthorized routing, and covert use difficult for people who lack local calibration and cannot conduct prolonged experiments. Failed attempts can consume time, generate conspicuous motion, and route carriers into supervised recovery areas.
Its value decreases when an attacker has unsupervised access, can measure the system repeatedly, can alter anchor geometry, or can install a launcher, guide, or powered actuator. Insiders and former operators retain learned skill and knowledge of recovery procedures. Maintenance personnel may have direct access to blockers, tension controls, latch internals, and reset paths.
Destructive attackers need not solve the trajectory grammar. They may cut, lift, dismantle, overload, jam, or bypass the supporting structure. Structural hardening and protected service access remain necessary when the asset justifies destructive entry.
Observation can be a security resource. A large jig, repeated failed swing, temporary support frame, or forced reset may be technically effective but socially visible. This makes the paradigm more plausible in inhabited warehouses, cooperative infrastructure, supervised rooftops, or community logistics than at isolated unattended sites.
The appropriate claim may be delay, deterrence, anomaly visibility, situated authorization, or resistance to casual replay rather than strong identity proof. Motor skill is not inherently secret, unique, or revocable. The system should be combined with role governance, route control, inventory supervision, structural protection, or complementary credentials when the threat exceeds local physical manipulation.
A deployment should state its assumed attacker, available observation, permitted setup time, control over maintenance interfaces, retry limits, and consequences of destructive failure. Without these boundaries, physical complexity risks becoming theatrical security.
WHY THIS EXISTS
Supports deployment selection, product claims, threat modeling, and comparisons with conventional physical access controls.
SOURCE CONTEXT POINTERS
- /concepts/pendulum-cable-security/RISKS_AND_CONTRADICTIONS.txt
- /concepts/pendulum-cable-security/details/imitation-jigs-robotic-replay.txt
- /concepts/pendulum-cable-security/details/enrollment-revocation.txt
- /concepts/pendulum-cable-security/details/probing-feedback-lockout.txt
EVIDENCE QUESTIONS
- physical access control threat model opportunistic attacker insider destructive attack supervised environment (semantic): The retrieved evidence mainly reinforced social supervision; stronger material could sharpen attacker categories