Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Good article about physical security and a intro to social engineering.

As an aside I think the easiest way to get into buildings which are associated with a technology company like this would be to apply for a job there. At worst you will be there for an hour. At best it would be eight hours. Also, there is a lot of downtime in between interview(s) or even just plain waiting on someone. You can get "lost" and if you get caught you could say "where is the bathroom".



We worked with other people's data and were contractually obligated to keep it reasonably secure. You could get inside a building, but probably not one with anything good in it.

To get into the server room you had to badge and code in and be visually verified before exiting the man trap. Computers that were able to access any of that were locked down and had no Internet. The network itself was locked down, with multiple separate networks.

Entry into the building itself required badging and visual verification.

Notably, this was only one facility. You could walk right into the other offices. I doubt anyone would have noticed. But, the secure office was pretty secure. You could get in, but not by social engineering. That office was pretty strict. Not even I could get in without my badge and visual verification.

Well, you could but it would take a lot of work and money. You'd have had to set yourself up as a potential client and we vetted client contacts and it required approval for each guest. We'd call headquarters and verify you were supposed to be coming, who you were, and things like that. We took no unscheduled, unvetted, unknown guests. Not even my kids.


I once worked for a hosting company. Getting in through the front of the data center felt like going through an airlock on a spaceship with someone having to verify your identity with 100% certainty at each gate. Going in the backdoor just required waving an electronic key in front of a sensor with no verification you were key's assigned user, and tailgating was definitely a possibility. Needless to say, a break in would likely have targeted the backdoor. I think the front door was a performance put on for customers getting a tour.


You can physically break into any facility, if you have enough force. Social engineering is a different problem.

In your case, no exiting the alarmed back doors for break. Breaks are taken by exiting the front doors or in designated break areas.

There were no security doors that weren't manned. Positive identification was required, as was approval. No exceptions.

We worked with proprietary data at that facility. Sometimes, we'd even have to put a team at the customer's site. Once, I had to personally do all of it as there were only two of us with government security clearances. For that, I had to be on a military facility.

The latter being really, really silly. I can't be specific but it is fairly well known that I modeled traffic. Yup... That's what I did and the USG determined the data was marked at a higher level that FOUO.


Unfortunately I’ve noticed the same, it’s a shame really. Was always a lot more convenient going in the back way if I was in a rush hah.


I worked at a place like that had all sorts of crazy protocols for data center access, including an armed policeman in the entry area, which was on a different floor, and rfid/pin access to various areas, including vendor areas.

...except for the cleaning crew, who inexplicably had elevator key codes and physical keys and nearly unfettered access. They used to smoke and play cards in the ladies room, which was huge, had a locker area and small table and was nearly unused otherwise.


I recall post 9/11 there was a great story where someone noticed once they finally got into the server room, "this was the wrong company."

Clearly, that was a more chaotic situation than normal, but physical security fails more often than you might think.


Layered and strict policies help prevent that. When I say strict, I mean the policies. If there is a security incident, you study it but not to blame someone. You study it to see where you can improve it.

My initial security training came from your tax dollars by way of the Marines. With the help of consultants, I designated much of our policy. Some of my employees spoke at Defcon, for example.

It's still possible for failure, but the chances are low. Each person entering is on a list - no exceptions. People who enter are NOT people who called us. We call you, at your HQ, and then do our vetting. Things like that. I am not going to go over all the methods, but we knew who was going into the facility beyond reasonable doubt.

Well, past tense. I'm retired.

You could still get in, but it's going to be difficult and expensive. Nothing is completely secure, nothing.


Not in a "high" security building you wont I remember going for an interview at huntings (an arms manufacturer) and I never got inside the main site the interview was in a room of the gate house.


I work for a company that has relatively high security and there are specially designated rooms that are located in the lobby area only for interviewing. YMMV


I went for a job interview with the UK Ministry of Defence, at a naval base. Once passed the gate house (with only an invite letter) I was free to roam the base. This was pre-9/11.


Only works for smaller companies/facilities. With larger ones the area interviews are done in is a separate security area. Same with the area where meetings with outside contractors are done.


Homeland? That's exactly what a FBI agent tries to do, but gets caught in that TV series. But yeah, guess it works most of the time.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: