The Register Home Page

back to article Security boss thought MFA would be too much security

ON CALL Supporting IT and keeping it secure is a serious endeavor. Which is why The Register lightens up Friday mornings with a fresh installment of On Call, the reader-contributed column that shares your tales of tech support trauma. This week, meet a reader we'll Regomize as "Colin" who told us about a recent gig at a customer …

  1. GlenP Silver badge

    Not quite the same but...

    A former employer installed clock machines for the office staff, ostensibly so they could generate an evacuation report in the event of a fire*, and mandated that this would apply to all staff. Only one person refused to use them, the MD that had signed off the policy in the first place!

    *The offices were small enough for fire wardens to do a quick walk through and check everyone was out. The evacuation report system never worked so the plan was to have "In" and "Out" racks for the swipe cards so a fire marshal would collect the "In" rack as they left the building. The next argument was over clocking out if you went out for lunch, the company said not to, which negated the whole exercise.

    1. Sam not the Viking Silver badge

      Re: Not quite the same but...

      As a very new trainee in the Design Office, I followed procedure and left the building when the fire alarm went off. It turned out to be a false alarm, the fire brigade were dismissed and we returned to the office to find Malcolm still sitting at his draughtboard, completely oblivious to the evacuation and he had failed to notice the lack of personnel around him. He had been in the toilet experiencing his own 'clear out' when the alarm went off having turned off his hearing aid. The 'walk-through' by the fire warden coincided with his transit within the building and because a roll-call had not been carried out he was not missed at the outside assembly.

      The resulting review called for extra fire-bells in the toilets.....

      1. Stuart Castle

        Re: Not quite the same but...

        I used to work in a university computer lab. We had a particularly obnoxious fire alarm. One day the alarm went off, and I went through the lab making sure the students left. This involved me shouting at the students and asking them to leave via the nearest exit.

        When I got near the fire exit, a student walked up to me asking what that awful noise was and complained it was interrupting his work. He even threatened to complain.

        I explained that awful noise was to warn him he might be in danger and that he needed to leave the building as quickly as possible. I also said he was welcome to complain, but that the university would be unlikely to do anything as they did have other computer labs he could use in other buildings on campus.

        1. Flightmode

          Re: Not quite the same but...

          I worked at an office some years ago where we had a slow, nasal woooop woooop woooop klaxon fire alarm. The building managers would conduct tests of the system a couple of times per year, which included leaving all the sirens running for about an hour as they walked through the building, making sure you could hear it from everywhere. This in itself was a pain. But even more of a pain were my immature colleagues who would record the klaxons on their phones and run around the office the following weeks with the recording on a loop, thinking they were hilarious. I believe they eventually did get a fairly stern talking to by management; both for disturbing their colleagues and, perhaps more importantly, desensitizing us to the alarm sound.

          1. Eclectic Man Silver badge

            Re: Not quite the same but...

            I was pretty 'relaxed' about fire alarms in buildings for decades. Then I was in a building that actually had a genuine fire.*. There is nothing quite like waiting for the fire alarm to go off after a minute or so (as usual), then when it continues, getting to the top of the seven flights of stairs which are your nearest emergency escape route to smell strongly acrid smoke and realise that you really should have left a minute ago when the alarm went off ..

            Now when I hear a fire alarm I leave the building. As the late, great, Barry Sheene** said, 'better a live coward than dead hero."

            *Some UPS's decided to go all thermal one morning.

            ** Twice world 500cc motorbike champion. His response to being asked why he never raced in the Isle of Mann TT races. His fastest lap record at Spa of > 135mph still stands after nearly 50 years of improvements to motorcycles, aerodynamics, brakes, tyres, engines etc.

            https://www.motorsportmagazine.com/articles/motorcycles/135-067mph-the-fastest-gp-of-all-time/?srsltid=AfmBOoqEISY_9gB3sDOC1BJS-tAcnub5A5IOVXBXdr5OGkuabDKhdBHu

            1. Stevie Silver badge

              Re: Not quite the same but...

              As I told a fire marshal who was telling us not to evacuate but to muster on a lower floor "There are only two kinds of people: Those who've never been caught in a building fire, and those who are never going to be caught in another. You can assume I'm out of the building when the alarm is sounding."

              1. Doctor Syntax Silver badge

                Re: Not quite the same but...

                I had a similar problem with the bomb alert procedures which involved leaving the glass walled building on one side, walking past the end of the glass walled building to muster on the other side of it.

                1. Excused Boots Silver badge

                  Re: Not quite the same but...

                  It’s quite possible that statistically, you would be better off by staying in the building if an explosive device does go off.

                  1. ButlerInstitute

                    Re: Not quite the same but...

                    We have a distinction between Fire alarm - leave the building, and bomb threat - go to "Internal Muster Area".

                    I worked for a while in BBC Television Centre where there had actually been a bomb go off outside (in a taxi, I think), so this was a real issue.

                    1. Doctor Syntax Silver badge

                      Re: Not quite the same but...

                      We had a bomb go off (different building than that in my OP). That was at the entrance. Everyone left the building and mustered at the far side. I wasn't there at the time but when I arrived an hour or so later it was quite a mess with windows blown in so remaining inside would have been a Bad Idea.

                    2. jpennycook Bronze badge

                      Re: Not quite the same but...

                      I remember being on the Central Line when BBC White City had a terrorist threat. Apparently the Tube trains were designed to deal with that sort of thing, so the driver kept going, but skipped the White City stop.

                  2. Doctor Syntax Silver badge

                    Re: Not quite the same but...

                    "It’s quite possible that statistically, you would be better off by staying in the building if an explosive device does go off."

                    Sampling bias. The statistics don't include figures given by those who elected to remain inside buildings.

                  3. Not Yb Silver badge

                    Re: Not quite the same but...

                    "It's quite possible that statistically..."

                    Whatever follows that sort of beginning is generally entirely imaginary statistics.

                    Most of the terrorist groups that would phone in bomb threats are more interested in property destruction (or business disruption via fake threats) than killing.

                    The worst loss of life has been from unannounced explosions, not threatened ones. (Oklahoma City wasn't called in as a threat first.)

          2. jdiebdhidbsusbvwbsidnsoskebid Silver badge

            Re: Not quite the same but...

            "perhaps more importantly, desensitizing us to the alarm sound"

            During one of my first job interviews out of university I was being escorted around a facility by my host when I asked her "what's that ticking noise?". She said "what ticking noise?". I said "that one ............ there it is again!". "Oh that?" she said, "that's the emergency alarm being tested every 20 seconds so we know it's still working, you don't notice it after a while".

            1. Doctor Syntax Silver badge

              Re: Not quite the same but...

              Somewhere near the Hampshire/Berkshire border?

              1. Andy A

                Re: Not quite the same but...

                There are others. I worked at one in Lancashire. Yes, it fades from the brain after a short time, and its ABSENCE then becomes an alarm signal.

          3. Andy A

            Re: Not quite the same but...

            The first place I worked was above a paint warehouse. If the alarm went, we GOT OUT. Once someone tested the Big Red Button on the way out. There was hell to pay when someone ignored the front door and went along the corridor to find that the Fire Exit was locked.

            The last place I worked had evacuation routes to safe assembly areas. Should the alarm go off, the instruction was to RUN. Cars found parked across any of those routes got their owners demoted to use the car park outside the gates.

          4. Anonymous Coward
            Anonymous Coward

            Re: Not quite the same but...

            One morning we had a bunch of firefighters burst into the room, lead by a white-hatted fire chief.

            "Didn't you hear the fire bell?"

            We explained that when the Alf the doorman had to leave his post he would lock the front door, so field engineers turning up with arms laden with kit and toolbags would lean on the doorbell until someone came to let them in.

            The fire bell was swapped for a siren within the week

            (Which reminds me that for some strange reason a D, I and P kept falling off Alf's noticeboard so it kept displaying "PLEASE ..SPLAY YOUR .ASS")

        2. David Hicklin Silver badge

          Re: Not quite the same but...

          Last place I worked had fire "zones" with 2 levels of alarm, A single tone meant be prepared to evacuate, a rapid multi tone meant "get out now".

          They were painfully - and I mean PAINFULLY - loud, and it was not fun being in an office with the single tone going off especially when they could run for 5-10 minutes. Thankfully noise cancelling headphones reduced it so levels that did not damage* my hearing

          * I am pretty sure it must have been doing that, they were really loud

      2. Plonker
        Mushroom

        Re: Not quite the same but...

        We had a similar toilet fire alarm test cockup. The fire bell was on the other side of the wall from the loos. A partition wall had been built right next to the bell, when the fire bell was tested it rang fine for the short time the test was active.

        But during the fire drill the bell rang for a much longer time, some weird resonant frequency stuff happened and bell change shape just enough to touch the partition wall and turn the ring into a dull thud.

        The old bloke that was in the loo at the time was know for his noisy clear-outs never heard a thing, he came out after the bell had stopped and wondered where every one had gone. He got a bollocking for ignoring the fire alarm. Then he had to be apologised to by the arse that didn't check the facts first.

      3. alain williams Silver badge

        Re: Not quite the same but...

        Many years ago I delivered a 1 week training course at IBM. I had to sign in at the front desk on arrival (as expected).

        One mid morning there was a fire practice so we all trooped out to the car park and had a roll call. Everyone was accounted for, but one extra person: me, I was not on any list of those supposed to be there.

        1. David 132 Silver badge
          Flame

          Re: Not quite the same but...

          I worked in the mid 2000s for a technology company in the South-West of England. We had regular fire-alarm drills - all muster in the car-park, in pre-arranged locations corresponding to the building number; team leaders verify those present against personnel lists - that sort of thing.

          Anyway, I remember two occasions of "genuine" fire alarms.

          The first was when a colleague spilled coca-cola over his keyboard; it was one of the legendary IBM Model M ones, so he casually washed it off under the tap, and put it somewhere to dry. Specifically, in the thermal test chamber that we would use to test cooling solutions (think of it as a large walk-in oven). He set the temperature for the chamber to a suitable level to quickly dry the keyboard... and then got distracted by something else and completely forgot about the keyboard merrily roasting at 200+ degrees C.

          The melting, bubbling plastic eventually generated enough smoke to set off the alarm, and he was very embarrassed.

          The second "non drill" fire alarm was when a very dopey and thoroughly unpleasant co-worker wanted some fresh air, so pushed the handle of the FIRE ESCAPE ONLY door and walked straight out from the office area to the car park. Which of course set off the alarms. When confronted later, her blithe and puzzled response was "oh, I thought that the sign just meant it wasn't the main exit door"; in fact, she was genuinely offended that we were all making such a fuss about it. Cue much head-slapping and muttering all round.

          Icon --> what else?

          1. Press any key

            Re: Not quite the same but...

            I'm always mildly amused by calm looking doors that have a sign on then telling us that despite appearances they are actually alarmed.

            1. Jou (Mxyzptlk) Silver badge

              Re: Not quite the same but...

              The door handles are kinda-locked-easy-unlock-in-emergency, clearly visible apparatus and sign with text that it will set an alarm. There is absolutely no excuse. Saying "calm looking" would not work for sure.

              1. pirxhh
                Boffin

                Re: Not quite the same but...

                In many buildings in the US, it's just a pushbar, not a handle, so it's possible to make a genuine mistake here.

                In our building, not so much - you have to break a cover and push a button to open the door when there's no alarm. This will trigger an alarm to building security. In a drill or actual alarm, security remotely opens all the exit doors.

                1. Claptrap314 Silver badge

                  Re: Not quite the same but...

                  By cutting power to the electromagnets? (Which is what I hope.) Fail safe is REALLY important...

            2. Not Yb Silver badge

              Re: Not quite the same but...

              You must be related to the coworkers who would leave the building using the clearly marked "Fire Exit Only" doors, disrupting the board designers from whatever they were doing for 10 minutes until the alarm timed out. We eventually printed up an even larger sign saying "NOT AN EXIT - EMERGENCY USE ONLY" and putting it on that door so that people wouldn't use it except in an emergency.

              Yes, I know the oddness of putting a "NOT AN EXIT" sign on a Fire Exit, but apparently management yelling at them about it didn't work.

          2. C R Mudgeon Silver badge

            Another unusual false alarm

            At school when I was about 10yo. Two kids were fighting and slammed into a wall, hard enough to activate the manual fire alarm that was mounted on it. (IIRC the alarm switch was one of these then-standard units.)

            I no longer recall, if I ever knew, what punishment was meted out.

            1. David Hicklin Silver badge

              Re: Another unusual false alarm

              Was a tech college when a student leaned back against the wall in the corridor whilst we were waiting for the lecturer to arrive - straight onto the fire manual fire alarm. We all heard the glass crash and they held still for a moment stopping it going off. Eventually they moved and off the alarm went

          3. Andy A
            Flame

            Re: Not quite the same but...

            One place I worked had notices on the fire escape doors claiming THIS DOOR IS ARMED.

            A usage of the term Fire which luckily I never had need to investigate.

          4. rskurat
            Facepalm

            Re: Not quite the same but...

            defensively "offended" because of being called out. Happens all the time.

          5. PB90210 Silver badge

            Re: Not quite the same but...

            We used to delight in going down the back stairs because it had one of those 'break glass' tubes on the fire door. They couldn't really complain because it could be the real thing

        2. Albert Coates Bronze badge
          Flame

          Re: Not quite the same but...

          Well, that could have been me. In the late 1990s I was also delivering a training course at IBM in Basingstoke on the 7th floor, where the canteen was also located. Mid-morning I glanced out the window, and something was minimally on fire in the kitchen. I drew the students' attention to the fact and carried on teaching. A couple of minutes later, the kitchens were a mass of flames, and IBM PC Server architecture (usually a rivetting topic) had ceased to be of interest. I asked the class, "Anyone fancy being burned alive?" Answers were all in the negative so I called security, "Fire in the kitchens on the 7th floor", the alarm went off and we all trooped down the stairs as described above.

      4. jdiebdhidbsusbvwbsidnsoskebid Silver badge

        Re: Not quite the same but...

        That sounds like a fairly innocent set of circumstances, but very good that the organisation learnt from it.

        Where I worked once, it was one the duties of the fire wardens to note the names of everyone who decided to stay at their desks instead of obeying the fire alarms wherever there was an evacuation exercise. Personally, I'm always one of the first out the exit after having experienced some exciting situations in my earlier career. Being several decks before the waterline, in the cold North Atlantic when the fire alarm sounds really focusses the mind. Especially when you're trying to go up the steps when the fire crew are telling you to get out the way as they are coming down, and you later raise that no, it wasn't a drill. Also, times when no matter how many decks up you go, there's no guarantee of open air when you get there.

        1. david 12 Silver badge

          Re: Not quite the same but...

          My Dad's procedure, ex-Navy and ex-fireman, was that you always identify the exits when you first enter, and plan to leave /first/ while the rest of the people are wondering what the alarm means, and if it matters. He didn't care what the alarm meant, or if it mattered: that was something you could find out tomorrow, or live without knowing.

          From him I also learned his scorn for and disgust with people who sit on stairs.

          1. C R Mudgeon Silver badge
            Flame

            Re: Not quite the same but...

            I don't identify exits on entering any building, but you're right -- it's a new habit worth cultivating.

            I've always done it when first checking into a hotel room, though: Where are the fire extinguishers? Which way(s) to the exit(s) -- and how many doors away? (Because if the hall is filled with smoke I might not be able to see the signage, either due to the smoke itself or to watering eyes. How many doors to crawl past on hands and knees, should it come to that -- that's a good thing to know in advance.)

      5. Christoph

        Re: Not quite the same but...

        Fire alarm test. I come down the stairs to the ground floor. There is a queue of people coming up from the basement, past the window, left and along to the building core, left to the main entry, left to the side door, then left and along outside the building past that window to the evacuation area in the car park.

        I step through that line of people, hit the locking bar on the window, step through and head for the car park.

        1. IanRS

          Re: Not quite the same but...

          I was once fire warden for the top floor of the office building and we had a small but genuine fire. The building was an L shape, with the main staircase in the centre and emergency exits at the ends. People going down one end found the emergency exit would not open and neither could they get back into the main office from there, so had to push back up a level against the people still coming down, go to the centre and back down. I was one of the last down the central staircase and found the fire doors at the bottom still shut. Everybody had gone through reception which was full of smoke. I pushed the bar - nothing happened. I kicked the bar hard, and it opened on the second try. I raised merry hell with building maintenance afterwards. My scope was just shouting at people to get out, not checking anything worked as it should.

          At the same office I suggested to the head of the fire team that all wardens went on an extinguisher training course (having been on one before and knowing they are a useful and often fun few hours). Some of them might learn that you point the extinguisher at what is burning, not send it through the flames above. I was told the only reason that there were extinguishers at all was they were a legal necessity. They were not there to be used.

          1. dave 76

            Re: Not quite the same but...

            At the same office I suggested to the head of the fire team that all wardens went on an extinguisher training course (having been on one before and knowing they are a useful and often fun few hours). Some of them might learn that you point the extinguisher at what is burning, not send it through the flames above. I was told the only reason that there were extinguishers at all was they were a legal necessity. They were not there to be used.

            I went through fire warden retraining not too long ago and was told that the advice now was that unless you were specifically trained as a fire fighter, the extinguishers were just there to aid you to exit the building, we were not expected or encouraged to attempt to put out the fire.

            The philosophy was that people are more important than things and we should get out as soon as possible rather than hanging around a fire.

            1. Not Yb Silver badge

              Re: Not quite the same but...

              Last place I worked the phrase was "You are neither requested nor required to use the fire extinguishers, but here's how to use them." Our only requirement was to instruct people to leave, and assist any disabled customers. Life was more important than anything in the building, and portable fire extinguishers aren't going to stop anything beyond a relatively small fire.

            2. Excused Boots Silver badge

              Re: Not quite the same but...

              "the extinguishers were just there to aid you to exit the building,”

              What, as ito prop open the fire doors?

              1. collinsl Silver badge

                Re: Not quite the same but...

                So if required you can beat down fire long enough to run/crawl past, or put out someone who is on fire I suppose.

          2. pirxhh

            Re: Not quite the same but...

            To be honest, when you are not trained, don't waste time with the extinuishers - evacuate.

            I'm trained on them as basic firefighting is part of the (mandatory for my job and very much fun) BOSIET course,to be repeated every four years.

            Extinguishers are very useful for minor and especially nascent fires, but as soon as one extinguisher does not cut it, evacuate - in fact, evacuate anyone not actively firefighting immediately. Smoke inhalation is deadly.

            1. Not Yb Silver badge

              Re: Not quite the same but...

              Best use of most fire extinguishers in anything beyond a very small fire is: Use fire extinguisher as battering ram, and get out.

        2. Excused Boots Silver badge

          Re: Not quite the same but...

          Many years ago working as a contractor at a site, there was a full-scale fire drill - we all knew it was a drill, but still. The 'evacuate now' alarm goes off and I’m on the 4th floor so head for the nearest staircase down to street level. When I get there, I find four or five people just standing at the bottom of the stairwell - the door won’t open!

          Thought about it for a second or two, then decided ‘screw this’, smashed the glass covering with my elbow, and smacked the big ‘Emergency Door Release’ button. We all exit safely. I can only assume that some wiring fault hd not released the magnetic lock on that door when the alarm went off as it should.

          I was half-expecting ‘some’ kind of blowback along the lines of ‘this has cost us money to have the system reset, the glass replaced etc. we expect compensation’ - but nothing. I can, again only speculate that someone realised the inevitable consequence of doing so.

        3. Anonymous Coward
          Anonymous Coward

          Re: Not quite the same but...

          Used to work in a shared office building where there were 3 exists and we were supposed to assemble at the front of the building. 1) The main front door to the building on the ground floor. 2) The rear ground floor fire door on the stair well, and 3) the rear basement fire door. Our office was in the basement, so exit 3 was our closest. Excluding the one company that was on the ground floor, everyone else's nearest was exit 2... but of course exit 2 and 3 required walking round the entire building to get to the front, so everyone except us walked past exit 2 and went out the front.

          Best of all, the person doing the test had no idea who was/wasn't in the building, so even though they were supposed to check that all the companies were out as part of the test, most of the time by the time we'd walked round the building we'd find they'd assumed everyone was out and had gone back inside.

    2. johnB

      Re: Not quite the same but...

      We had the same nonsense at a largish govenrnent office - record arrival & departure by completing a register.

      Of course Fred never did that when popping out for 10 minutes to get his morning bacon sandwich. So as long as the fire took place outside the 10 minutes the system would work. Otherwise we'd be sending firefighters into a burning building to look for a member of staff who standing outside eating said sandwich watching the activity.

      Fortunately the system quickly got forgotten.

    3. Blackjack Silver badge

      Re: Not quite the same but...

      Anyone who happened to be visiting the building and wasn't an employee wouldn't be clocking in or out so the thing was pointless even if everyone had been using it correctly anyway.

      The things are meant to check if workers are in the building and that is it.

      1. The Oncoming Scorn Silver badge
        Flame

        Re: Not quite the same but...

        Fire drill at the slaughter house, we all piled out of the facility into a balmy -19C or lower. Once my name was called & checked off, I went & sat in the "warmer" environment of my truck.

        This kept people outside for longer as they did a second head count as someone was missing & now found 2 people missing.

        The other party was eventually found fast asleep on a pile of flat packed boxes, having slept through everything - Complete with pillow & a still lit ciggie in his hand, very much in the vein of "I'm alright Jack".

        He soon had opportunity to get much much more beauty sleep during the day.

        Not only but also somewhat similar........

        Colleague had a ticket in a building at GSK, a clean room facility, on arrival the process was to sign in & then put on paper overalls, hairnet, snood & overshoe coverings.

        The front desk was empty, so he signed himself in, went & changed & went in search of the PC, in a suspiciously empty building.

        Having located said machine, he began his diagnostic's... only to be rudely interrupted by a fire marshall (or similar) on a final walk through who loudly & ever so not very politely enquired as to

        "WTF are you doing here? We are about to fumigate the building.... Didn't you see the signs outside?"

        What signs outside? came Paul's response.

        That sparked a review of procedures.

      2. pirxhh
        Coat

        Re: Not quite the same but...

        On many industrial sites, there's a T-card* system to record anyone inside. Nowadays, it may be electronic with turnstiles to get in and out while scanning your access card - including visitors who get a temporary card. I have quite a collection of T-cards acquired during my career. Tomorrow will be the last day of my 20-year tenure in the company, I'm just about disposing of those cards while clearing out my stuff for semi-retirement...

        * From the traditional shape of the cards, similar to a t-shirt so they can be stuck into a slot without falling through.

    4. blu3b3rry Silver badge

      Re: Not quite the same but...

      Was a fire marshal at one place where attempts like that were made. Thankfully kiboshed after during a fire drill we were handed a three hour old roster without any prior mention that a roll-call was required. We'd had multiple drills previously and never done so, as the keycard system only recorded entries to the building and not exits.

      As a result a good third of the people listed weren't on it, and we had a good fifteen or so who were present at the muster point yet not on the list!

      Needless to say it wasn't bothered with again.

    5. DS999 Silver badge

      A clock system would never work

      Forget lunch, are people supposed to clock out every time they step outside for a smoke or walk across the street to grab something not sold in the company vending machines? Good luck getting compliance on that (and good luck not having some beancounter want to ding you for only "being in the office" for 7:30 every day because you always leave for the full hour of lunch and step outside for two 15 minute "coffee breaks")

      If they have a card entry system where you had to card in AND out, and tailgating rules were strictly enforced, then you'd know who is inside. It wouldn't be something physical like a shelf of time cards for the fire marshal to grab, but I'm sure they could work out a solution for that.

      1. collinsl Silver badge

        Re: A clock system would never work

        In the DC where I work they use the fence turnstiles to check people in/out (since you can't tailgate) and the fire alarm triggers a printer which spews out a building occupancy report that they can do a check from (based on who was in the fence line at the time the alarm was triggered I presume)

    6. Bilby

      Re: Not quite the same but...

      I once was supervisor for a small team working in a warehouse ante-room that had been repurposed several times. Thos was part of a very large campus with extensive grounds. At the back of the room was a fire exit, but at some point a steel fence had been added to create a storage area enclosing a five metre deep space outside the door, used by the groundsmen/gardeners to store their tools and equipment.

      To prevent theft, this area was secured with a padlock after hours, but as it was a fire exit route, the head groundsman was under instruction to unlock it during working hours, and my first responsibility each morning was to exit via the fire door and check that the gate was, indeed, unlocked.

      One morning, I found that I couldn't open the fire door, as a heavy object had been placed against it. So I walked all the way round the building to investigate.

      The object in question turned out to be a pallet, on which was stacked a dozen jerrycans full of petrol.

      1. JimCr

        Re: Not quite the same but...

        Well.... it was a "fire door". The petrol completed the equation.

  2. Anonymous Coward
    Anonymous Coward

    Ah the C-Suite

    Ah the C-Suite.. the most likely people be *sent* a phishing email by a couple of orders of magnitude over rank and file employees, and as a result a couple of orders of magnitude more likely to be phished. If you have the data available to you, do the analysis in your own org and you might well be surprised.

    We rolled out MFA across our entire org except for one person, the CEO.. but I think the problem was that nobody was brave enough to finish the job. Undeterred, the CISO rolled up their sleeves and patiently explained the elevated dangers and catastrophic consequences of the CEO being compromised. The CEO agreed that they should be treated the same as everyone else. A couple of months later the CEO fell for a phishing email.. and the attackers failed to get in because of MFA. Job done.

    1. JLV Silver badge

      Re: Ah the C-Suite

      Not to mention that when you think about it, if a company follows a predictable jsmith/johnsmith@foo.com pattern, jbezos@amazon.com or andyjassy@amazon.com is pretty much a known public domain email, making it all the more in need of protection.

      Though I’d wager the really big corps CEOs have underlings vetting the mail anyway.

      1. Aladdin Sane Silver badge

        Re: Ah the C-Suite

        Though I’d wager the really big corps CEOs have underlings vetting the mail anyway.

        Can confirm. Considering most emails to CEOs are complaints, they're handled by the exec complaint team.

        1. LessWileyCoyote

          Re: Ah the C-Suite

          When I worked at a (very) large communications firm, emails to the CEO had to be printed out for him to scribble action/answers on. He didn't actually use a computer, that was for his underlings. Presumably they all shared his password in order to do this.

          1. A.P. Veening

            Re: Ah the C-Suite

            Presumably they all shared his password in order to do this.

            More likely just (shared) access to his mailbox.

            1. Chrissy

              Re: Ah the C-Suite

              "More likely just (shared) access to his mailbox."

              Oh sweet summer child.

              A mailbox delegation would've been used if they'd ever thought to ask IT "What's the correct way to access someone else's mailbox?", but, as Fantasy Island isn't a place, unless you have the hearing of a bat, or Personal Assistant A had already asked you to change the password of Executive Z allowing you to intercept and halt that type of use and instead divert them off to delegation, password sharing is going on somewhere high up, guaranteed, as "those petty IT policies don't apply to us".

        2. WonkoTheSane

          Re: Ah the C-Suite

          AKA /dev/null

      2. GlenP Silver badge

        Re: Ah the C-Suite

        Nearly all out phishing attacks come from LinkedIn data scraping*;they are rarely to the C-Suite but do come "from" them.

        Three times we've had new staff who's email addresses would not be in the public domain at all, except that they've updated their LinkedIn profiles, receive a scam "Welcome to ..." email from the CEO.

        1. Timo

          Re: Ah the C-Suite

          I think it's something with the Microsoft identity service, someone has figured out how to skim lists of people, or someone is selling lists of names that they've gotten there.

          I joined a company and once I got access to my work computer some of the first emails I got were spam. I barely knew what my email address was. Only place the address would have been is with Microsoft!

        2. Keith Langmead

          Re: Ah the C-Suite

          "Nearly all out phishing attacks come from LinkedIn data scraping*;they are rarely to the C-Suite but do come "from" them."

          Yeah that's what I've seen most often. Email "faked" as from the CEO/MD* etc to an underling telling them to process a payment / make a change etc. Bonus points for those companies who have an About Us page including names/titles/email addresses, or active LinkedIn, where it becomes obvious who the bookkeeper / finance manager is, who is obviously most like to have access to actually make those requested payments.

          * Generally not even bothering to try faking the actual from address any more (presumably due to SPF/DKIM) and just faking the display name... which sadly still seems to work. "CEO Bob has sent me this email!", "Clearly not... look, it's from "CEO Bob" <l33thaxor@dodgydomain.com>... that's NOT his email address!!!"

      3. FrogsAndChips Silver badge

        Re: Ah the C-Suite

        A cybersecurity firm that we employ has addresses in the form john.smith123@domain.com where '123' are random digits per user to make the address less predictable. One of the auditors admitted it didn't really prevent them from receiving unsolicited emails.

      4. jdiebdhidbsusbvwbsidnsoskebid Silver badge

        Re: Ah the C-Suite

        "Though I’d wager the really big corps CEOs have underlings vetting the mail anyway"

        Not just email, but all things getting in the way of actually doing work. I remember our workforce (me included) complaining to the c-suite about the awful corporate bit of software that we were all mandated to use to record our timesheets. (last job on a Friday before the weekend, perfect way to leave a sour taste in the mouth and really make staff not look forward to the Monday morning but they just didn't get that). HR insisted their user testing had confirmed it was easy and simple. They didn't think that it was because being HR and all overheads, they didn't actually do proper timesheets, so no wonder it was easy for them. The c-suite also insisted it was all fine and the problem must be with us (some of "us" were actually professional software engineers specialising in human factors issues but would HR ask for advice? of course not). Then we learned that the c-suite didn't do timesheets either so they had no idea why we were complaining. The software was eventually improved, a bit, but again with no chance for the actual users to be part of that change. To this day it's still a source of aggravation and the corporate tool for ruining what might otherwise have been a good week.

  3. Jou (Mxyzptlk) Silver badge

    CYA

    If the C-Suite insists on going against your recommendation you can only "CYA". And since we don't have USA-TV-level censorship I can say: "Cover You Ass". On Youtube you have to say "CYB", "Cover Your Bases", for more than ten years now.

    1. Andy Taylor

      Re: CYA

      Or as they say on Slow Horses - London Rules.

    2. Bebu sa Ware Silver badge
      Windows

      Re: CYA

      I always thought that CYA was for See Ya (See you, au revoir etc) — I must have got off the bus one planet short of Earth.

      Curious that "cover your ass" is preferable to "cover your arse" in ning-nong land when the first would presumably have the sense of a stallion "covering" a mare.

      CYB could just as easily be cover your bum — advisably so considering the crap that lurks behind the U-tube of Youtube.

      MFA/2FA is probably an ongoing conflict but the fight against the evil of shared accounts continues down to this day. Mostly sheer laziness, the residue just appalling ignorance.

      † by the time I realised what ICQ stood for, it was no more.

      1. Jou (Mxyzptlk) Silver badge

        Re: CYA

        There is no three letter akronym that has not gazillion meaning depending on the context. Ask the AAAA (Association Against Akronym Abuse).

        1. Aladdin Sane Silver badge
          Coat

          Re: CYA

          It's all Greek to me.

          1. David 132 Silver badge
        2. A_O_Rourke

          Re: CYA

          or the AAAA - Association Against Aberrant Apostrophe's

          1. An_Old_Dog Silver badge

            Re: CYA

            Sign me up for that!

            Too many times I've seen apostrohes simply sprinkled through text as salt sprinkled upon mashed potatoes.

            1. collinsl Silver badge

              Re: CYA

              Too many time's I've seen apo's'trophe's simply sprinkled through text a's' salt sprinkle'd upon mashe'd potatoe's.

              FTFY

          2. GrizzlyCoder

            Re: CYA

            The founder member being the late and esteemed Mr Keith Waterhouse I believe

        3. David 132 Silver badge
          Happy

          Re: CYA

          I think I've told this anecdotette around here before, but... having recently immigrated to the US, I followed in traffic a white pickup truck, on the tailgate of which was printed the slogan AAA Battery Installation Service.

          I spent longer than I should admit thinking - and feel free to imagine this in the voice of The Simpsons' Dr Nick - "what a country! they even have people to install those little pinky-finger-sized AAA batteries for you!"

          It was actually - of course - the American Automobile Association's vehicle battery installation service. Or at least, I hope so.

          1. PRR Silver badge
            Boffin

            Re: CYA

            > AAA Battery Installation Service.

            Less so today, but usta be when you looked in a Telephone Book there were a LOT of "AA Bail Bonds", "AAA Termite Fumigators", and "AAAA Towing", to get to the top of their respective section or alpha ordering.

            1. Huw L-D

              Re: CYA

              This is why ZZ Top are named ZZ Top.

              1. phuzz Silver badge

                Re: CYA

                I do hope that they have a UK tribute act called Zed Zed Top.

        4. Christoph

          Re: CYA

          I once heard of someone implementing a network of ATMs on an ATM network. Though as far as I know they weren't using ATM fonts.

          1. Jou (Mxyzptlk) Silver badge

            Re: CYA

            ATM I cannot understand a thing you say.

        5. Huw L-D

          Re: CYA

          Join COCOA. The Campaign Opposing Contrived Outrageous Acronyms.

        6. Richard Pennington 1

          Re: CYA

          I'm retired now, but at one previous employment my boss was (among other things) the Keeper of the Acronyms. His "public" collection of on-project acronyms ran to 130 pages (including many cases where the same abbreviation had multiple meanings [e.g. PM = afternoon = Project Manager = Prime Minister]. His private collection ran to 1300 pages...

          1. Jou (Mxyzptlk) Silver badge

            Re: CYA

            So he hat the next level, aka the AAAAAAAAA, aka the A9, in there? The Allied Anonymous Association Against Acronym Abuse Altogether Anytime Anywhere?

          2. collinsl Silver badge

            Re: CYA

            When I did a year's placement in Air Traffic Control engineering some years ago their intranet had a glossary of acronyms to which you could propose additions or corrections - I'd assume they still have to have such a thing and that the list has only grown massively!

        7. Daniel Pfeffer
          Joke

          Re: CYA

          Ask the AAAA (Association Against Akronym Abuse

          Or the American, Asian and African Association Against Automatic Acronym Abuse (the AAAAAAAAA).

      2. FirstTangoInParis Silver badge

        Re: CYA

        MFA a conflict …. Depends how tech savvy / intolerant your users are. In a small volunteer charity situation, MOST users are way down the tech savvy curve and some are tech intolerant. Thus introducing MFA is a super big deal which has to be severely proven to work in all use cases before going live.

        1. Anonymous Coward
          Anonymous Coward

          Re: CYA

          Wait until you come across a user who can't type 8 digits into the MFA field before the display goes to the next number...

          1. Jou (Mxyzptlk) Silver badge

            Re: CYA

            Found one. Me. I'm here. And I blame the procedure and the stupid non-adjustable-for-me mobile screensaver after 30 seconds pushed by company policy (among other things).

            Fire up the laptop, log in (here no MFA needed since by definition no internet without VPN), unlock the phone beforehand, VPN, asks for MFA 8 digit number, and I see the timer below 5s, so I tap somewhere on the phone, if it has not already locked, wait for the next code, want to type it in, then something from autostart ate one of the digits since it HAD to take the focus for a ten'th of a second at the right time, me cursing, redo from start....

            And add when the VPN acts up, takes a bit too long to ask for the RSA key, the phone is already locked since 30 seconds, and an enforced alphanumeric 10 digit code is needed to unlock the phone. Great to type if you got pre-teen fingers, which I don't. So I have to enter the phone code twice quite often. Oh, the VPN timed out waiting for the code. Redo from start.

            Not all implementations are in my hand, but customers hand, customers laptop, customers phone for MFA... Some MFA needs to be relaxed, in my case the phone-lock-enforcement changed to two minutes so I don't have to tap it constantly just to keep it awake... Or just change it to certificate VPN, which is by far the most relaxed...

            (By the way: Of course the laptop has a bitlocker pin, length min 10 and alphanumeric enforced, but those keys are big enough, and the wrong language layout is something I can handle, so no problem there)

            1. Robert Carnegie Silver badge

              Re: CYA

              Some phone apps may prevent the phone from locking - I use an iPhone grocery shopping list called "Out of Milk" - but you probably can't just install whatever on your work phone?

          2. C R Mudgeon Silver badge

            Re: CYA

            There used to be, and maybe still are, time-based MFA implementations that used a dedicated key fob or the like, which displayed a code that changed every N seconds.

            ISTR that at least some of those implementations would actually accept not just the currently visible code, but also the one on each side of it -- including the future code that the user's fob was going to switch to next (I.e. each code was "live" for 3*N seconds). The server would then analyze which of the three codes any given user tended to provide, and use that to compensate for any clock drift in that user's fob.

            Very clever.

    3. Philo T Farnsworth Silver badge

      Re: CYA

      Just for the record, "ass" is allowed, at least on radio in the US.

      I'm not sure about teevee since I don't watch any.

      It's all part of a coarsening of the dialog since the whole Clinton Impeachment/Monica Lewinski imbroglio when it became permissible to utter the word "penis" on the evening news.1

      I've heard things on AM drive time radio that I would have found myself quickly out on the street for had I even thought them when during my radio jock days.

      As a side note, one acquaintence of mine got fired from a major Los Angeles FM station for using the word "penis" on the air back in the 1980s, so times and standards have definitely changed.

      Another got canned in Houston for using the word "bucket" because the managment merely thought he said something that rhymes with the word.

      Go figure.

      _______________

      1 Thanks, Kenneth Starr. I hope your punishment requires you to weat a stained blue dress for all eternity.

      1. Solviva

        Re: CYA

        Penis? Surely he was talking about one who plays a piano? Hardly a sacking offence...

      2. phuzz Silver badge

        Re: CYA

        In the UK they can show a penis on the evening news, as long as it is post-9pm and flaccid. (I don't think a penis ever has been shown on the news, except perhaps Michelangelo's David or similar)

        1. collinsl Silver badge

          Re: CYA

          I remember Penny Mordaunt on some TV programme or other stating that for her maiden speech (IIRC), which is supposed to be humorous in some regard, she talked about her Royal Navy reserve officer's training, including a section on caring for your penis and testicles in the field and how the women on the course had been "issued the incorrect equipment". She had to get the parliamentary staff to check if a) she was allowed to say "penis and testicles" on the floor of the house (the decision was that "as they were things, they could be mentioned") and 2. whether or not they had been said before (they had not).

  4. Eclectic Man Silver badge
    Unhappy

    Regarding "yelling"

    A director yelling at a subordinate is only appropriate when there is excessive 'background noise', such as in an engineering shop floor, in an active combat situation, or when the person is a long way away and normal volume would not be noticed. The description indicates that the director was not behaving properly and determining what had caused the problems and was overly emotional. Not someone to be trusted with a high pressure high responsibility position.

    1. andy the pessimist Bronze badge

      Re: Regarding "yelling"

      In the test area noone can hear you scream.

      The test are was recorded at 94db,just below mandatory ear defenders, ànd one down tester.

      I blame test areas and motorhead concerts.

      1. FirstTangoInParis Silver badge

        Re: Regarding "yelling"

        One location I was in had a fire alarm so loud it made your body vibrate. Like a Vulcan bomber fly past but without the thrill of seeing that.

    2. ttlanhil

      Re: Regarding "yelling"

      Those are times when it's appropriate to yell TO someone, but not AT them

    3. Confucious2

      Re: Regarding "yelling"

      I was yelled at by a CIO for trashing their security.

      She went red in the face as she asked my if I wasn’t told which buttons to press on my three day induction.

      It was my first morning, the CFO called me in and told me to ignore her as I’d done exactly what he bought me in for.

      The CIOs idea of security was telling people exactly what keys to press so, apparently, I shouldn’t have taken a hidden option and given myself qsysopr rights.

  5. Anonymous Coward
    Anonymous Coward

    Have you ever been told to make IT worse

    It's happening to me now.

    I have to train the AI so that it can replace me as the AI will be much better than me at doing my job ...

    1. Anonymous Coward
      Anonymous Coward

      Re: Have you ever been told to make IT worse

      I do hope you have a carefully designed training plan for it, for later appearance in "Who, Me?"

    2. Eclectic Man Silver badge

      Re: Have you ever been told to make IT worse ?better?

      I assume that by 'better', your management means "cheaper"?

      As in: cheaper to run, no overtime payments (to the AI), as opposed to "more reliable, and with an improved understanding of what is acceptable conduct, and what is legally permissible in the relevant jurisdictions in which your company and its products are employed and less likely to just make things up."

      (Good luck.)

      1. FirstTangoInParis Silver badge

        Re: Have you ever been told to make IT worse ?better?

        And, pray, what happens when the AI budget runs out of tokens? I suggest your going rate will then be the equivalent of many thousands of tokens. Of the folding kind.

        1. WonkoTheSane

          Re: Have you ever been told to make IT worse ?better?

          Indeed - Bank of England (or US Mint if applicable) gift tokens

  6. Kurgan Silver badge

    MFA is for underlings

    MFA (and every kind of useful but annoying security) does not apply to bosses, only to subordinates.

    It has always been like this.

  7. RockBurner

    Have you ever been told to make IT worse?

    Frequently and often.

    Part of the deal when you're an IT worker in a non-IT market company. (and often even when the company IS in an IT related market)

  8. tatatata

    I think the COO made the right decision to roll-back the change. Apparently, the change was based on insufficient testing and on promises of MFA. In addition, not being able to send invoices will kill most companies. Yes, the invoicing software must be debugged/replaced/..., but you cannot stop billing your clients waiting for some software company to fix the MFA . Colin may have found it stunning, but if his invoice would not be paid due to the introduction of MFA, he would also be annoyed.

    1. vtcodger Silver badge

      Dealing with reality

      Mostly I agree. The COO had to make a decision based on inadequate information. And, very likely, he had to make it now. Not in eight hours. Not in three days. Now. The consequences of a screwup in invoicing are presumably serious and immediate. And that's what he was potentially looking at. The consequences of rolling back to a slightly flawed system that has presumably worked OK for years would presumably be minimal. I know what I'd do. And what most people would do.

      Of course once things were sorted out, they probably should have gone back to MFA. Perhaps after quite a bit more testing specific to their use case. And quite likely a few fixes and work around in the new system.

      One thing I learned in the 1960s early in my IT career is we IT folks tend to view the world from a rather odd and quite optimistic place. Unfortunately, the real world tends to be a bit flawed. It would be better I think, if both we and bosses acknowledged that and accommodated to it. It's not like we have a choice y'know.

      1. jdiebdhidbsusbvwbsidnsoskebid Silver badge

        Re: Dealing with reality

        "The COO had to make a decision based on inadequate information. And, very likely, he had to make it now"

        She, not he, it says so in the article. Shes can be rude and aggressive too.

    2. anothercynic Silver badge

      Most MFA allows you to have exceptions, such as the invoicing system with a shitty MFA implementation. Thus - you exempt invoicing app X from MFA until such time that vendor for invoicing app X has an improved MFA implementation. Then you *test* said invoicing app X with the COO and other tame underlings to check that the MFA now works as expected, and then implement it.

      1. Screepy

        Precisely this.

        It's very straightforward to create a group policy that has a list of accounts that are exempt from MFA.

        Think service accounts etc..

        When we rolled out MFA at our org quite a few years back, we had a good 30-40 accounts that could not have MFA on them for various reasons. We still rolled it out to the rest of the org of 3000+- users.

        There was then a follow up project to slowly and careful churn through the service accounts to get them over to MFA.

        We still have 3 service accounts that aren't protected by MFA, so we have additional monitoring on them etc.

    3. C R Mudgeon Silver badge
      Pint

      "you cannot stop billing your clients waiting for [a software fix]"

      Indeed.

      I was once out TGIW'ing with coworkers (for reasons, the end of our work week was Wednesdays) when the Accounts Receivable clerk came to our usual watering hole to find me because that week's invoices were all printing with Invoice Numbers of "*****".

      I knew what was wrong before I was out of my chair (as I'm sure you do now). Fixing it, on the other hand, was a royal PITA. I had to pull an almost-all-nighter extending the field to six digits [1] so that the A/R guy could reprint the invoice run first thing in the morning.

      The point of the story is that waiting till the morning to fix the code simply wasn't an option; the invoices *had* to go out in Thursday's mail.

      [1] The sales-order system was a mess of cut'n'pasted'n'hacked-on code (in SCO FoxPlus, a dBase sort-of-clone). I had to do a lot of tracing the invoice-number database field through many code paths, to find all the places where the display format needed to be adjusted.

      It was a good thing the A/R guy caught me early enough in the drinking cycle that I was in shape to do the work!

      ---> for what I had to leave unfinished that night...

  9. cookiecutter Silver badge

    i no longer drive so i can't be bullied into going to places at short notice. since I, like many it ppl tend to be ppl pleasers Ive removed my ability to go to any site without notice regardless of severity.

    fuck em

    1. LessWileyCoyote

      Normally the executive summary goes at the beginning, but I agree it works better at the end in this case.

  10. MTimC

    More security isn't necessarily better. The role of the security function includes ensuring that legitimate actions happen at optimal costs. Missing this is a current issue in NHS systems usability.

    MFA is also often abused where it relies on another service that has much lower risk controls - eg using a phone's authentication model, that's there to protect <£1000 of cost to protect financial transaction of > £10,000.

    It would be nice if the work around object capabilities finally makes it into s/w development so that the usecases consider required authorisation, delegation, etc, and get rid of the silo walls between IT and security.

  11. An_Old_Dog Silver badge

    This 15-Year-Old Animation Illustrates the Problem

    Why I NEVER fix a Computer for FREE

    1. C R Mudgeon Silver badge

      Re: This 15-Year-Old Animation Illustrates the Problem

      Uh huh. Touch it once, and all future problems are your fault.

  12. BartyFartsLast Silver badge

    I've had that accusation leveled at me "all our computers are off, your new network install has destroyed our business and it's costing us a fortune, you have to be here now and we're expecting compensation for the lost work hours"

    Turns out they thought the new cabinet with patch panel and switch actually powered the computers and hadn't realised that condensation dripping off a kitchen cabinet into a toaster might be the cause and have trippped a breaker.

    Obviously I billed for an emergency call out fee, travel time and an hour on site.

  13. xyz123 Silver badge

    There's a MAJOR MAJOR UK telecom infrastructure company who's "security" is if you plug in ANY new PC in the office via ethernet, it pushes you to an install page which sets up corporate apps, email, logins/passwords, permanent software licences for Microsoft, Oracle etc.

    Then you can just take the laptop home. Their entire security is based on "no-one would walk into our offices and plugin a burner laptop they just bought"

    1. Anonymous Coward
      Anonymous Coward

      How much did you make when you sold the second one?

  14. Doctor Syntax Silver badge

    "decided to improve the security of its Microsoft 365 implementation"

    Surely there are more direct means to achieve that aim.

    1. Korev Silver badge
      Mushroom

      You forgot the icon -->

  15. Niek Jongerius
    Facepalm

    The same person claimed Colin's work on M365 caused a power outage

    Post hoc ergo propter hoc.

    -Niek.

  16. Stevie Silver badge

    Bah!

    Was ordered to learn about maintenance and development life cycle process by big manager "as a trial".

    Was ordered to use maintenance life-cycle process for a new project. I informed big manager that was the wrong procedure - was made to wear the cone of not cooperating with management.

    Went through the tedious and very unpopular process with staff.

    The end of the process was that a requestor sign-off for all steps had to be gotten before rolling out.

    Repeated requests for sign off from original requestor went unanswered. Original requestor was ... big manager.

    Rolled out sans sign-off.

    No-one ever used the life-cycle procedures again.

  17. Taliesinawen Bronze badge
    Facepalm

    The Four Pillars of Microsoft Resilience

    Note on Compliance: If you are researching this from a financial services perspective, Microsoft tools are frequently mapped to the 5 Pillars of DORA (Digital Operational Resilience Act) or the 5 Pillars of the Azure Well-Architected Framework (Reliability, Security, Performance, Cost, and Operations). However, for cyber and tenant resilience, the Anticipate, Withstand, Recover, Adapt framework is the industry baseline. ref

    1. Doctor Syntax Silver badge

      The five pillars of MFA

      You know where your phone is, it's with reach, it hs a useable charge, it has a signal and whoever has it is you.

  18. BasicReality Bronze badge

    Worked at a call center several years back, it was fun telling the customer I was speaking to that the fire alarm had gone off and we had to evacuate the building. Call back and your call will be routed to another center. At least the customer was pleasant about it. Happened with a tornado warning as well. “I’m sorry, I have to disconnect now because we’re all supposed to sit under our desks.”

    1. Excused Boots Silver badge
      Coat

      Was the headset cable too short for you to sit under the desk and continue with the call? Sounds like the call centre (centre) management missed a trick there!

      Ditto the cables to the screen, OK there is a tornado barrelling down in your direction, but surely you could spend a few minutes manhandling the monitor under the desk so as to carry on working.

      When will someone start thinking about the poor shareholders!

      >>>> Yes, look I’m getting it.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon