The Register Home Page

back to article Hackers shoveled snow for company, were rewarded with network admin access

PWNED Welcome back to PWNED, the column where we document serious security failures in hopes we can all learn from others’ mistakes. This week, we’ll talk about how a lack of physical security can allow threat actors to take control of your network. Have a story about someone leaving a gaping hole in their network? Share it with …

  1. Jou (Mxyzptlk) Silver badge

    Nice article!

    Work result for today from this: "ESC1 ESC4 ESC8" and is my default way to set PKI up affected by this? I hope not, but I shall see...

  2. Pascal Monett Silver badge

    Interesting

    No access security on the conference room Ethernet port ? Normal, it's manglement that uses that and they're time is too important to be bothered.

    60 employees with the same password ? WTF ? Was there a conference where somebody wrote on the whiteboard "winter2023!" and everyone present agreed ?

    1. Victor Ludorum

      Re: Interesting

      Many orgs have a 90 day password policy, so of course employees will just use the season and year as their password. Add a 'special symbol' or two and you've got a 'strong' password...

      1. Anonymous Coward
        Anonymous Coward

        Re: Interesting

        The 90 day mandatory password change has long since been recognized as poor practice by NIST and NCSC. If you're in an org that still thinks it's a good idea, you've probably already been pwned.

        1. Anonymous Coward
          Anonymous Coward

          Re: Interesting

          My company dropped a 49 day password change policy. It's now 180 days.

          So instead of <Month><Year><+padding> it's now <Season><Year><+padding>.

          1. Cris E

            Re: Interesting

            And padding is easily typed asd or qwe and special char is always last so you only need to move your hands once and it's often an unshifted char and yes, still "secure".

          2. Giles C Silver badge

            Re: Interesting

            We have a one year password change policy, doesn’t help that I have an admin account which I only use for logging into network switches and when that expires you don’t get a warning - just locked out.

          3. Giles C Silver badge

            Re: Interesting

            We have a 1 year password reset policy, mind you sometimes it still catches you out as I have two account a normal and an admin one, as the admin is used for network switches I don’t get a warning when it is due to expire….

        2. mgb2

          Re: Interesting

          There are plenty of security practices that are seen as outdated by those who are knowledgeable, but I bet nearly every insurance provider still has frequent password changes on their requirements checklist.

          1. Roland6 Silver badge

            Re: Interesting

            >” There are plenty of security practices that are seen as outdated by those who are knowledgeable”

            Yet journalists continue perpetuate the mistaken belief.

            Periodically I see WiFi security articles written in the last decade which still advise the hiding of a WiFi network’s name (SSID); a practise that had been debunked prior to 2006…

          2. Claptrap314 Silver badge

            Re: Interesting

            My last job was at a health care middleman company. Filling out security surveys became my primary duty. Can confirm.

          3. Anonymous Coward
            Anonymous Coward

            Re: Interesting

            > security practices that are seen as outdated ... frequent password changes

            Good news, everyone! A chip designer you are all certainly familiar with, A Really Mega one, has just this week found out about this security feature.

            We'll all be safe now.

        3. chivo243 Silver badge
          Devil

          Re: Interesting

          At a previous gig, I gave up on password changes, too much push back from the department that made sure we were paid. HR also groused, but if finance hadn't groused, HR would have been changing their passwords.

        4. AustinTX

          Re: Interesting

          The "orgs" don't think it's "a good idea". They're either unaware of what their nitwits are doing, or powerless to enforce it. I sat down with such a nitwit and pretty princess just smugly told me she would keep using the same strategy for new passwords. Ugh.

        5. Kurgan Silver badge

          Re: Interesting

          Yes, and EVERY BUSINESS IN ITALY uses this practice and it's the best practice of course. It's NEEDED. LOL. Idiots.

        6. Col_Panek

          Re: Interesting

          Perjhaps the principle is that annoying legit users is the best way to raise awareness of security. I dunno.

      2. Kurgan Silver badge

        Re: Interesting

        Exactly. Every "strong" and changed over time password is like:

        MonthYEAR!

        SeasonYEAR!

        Supplier_nameYEAR!

        Customer_nameYEAR!

        1. snee

          Re: Interesting

          Ah, I see my company's guest WiFi network template there

    2. Anonymous Coward
      Anonymous Coward

      Re: Interesting

      We have a strict if you don’t know them and can’t see an ID then challenge them policy for people in the building. Yes this did lead to the MD being accosted by someone who was new to the business but it’s still policy. Someone came in one day to fix a vending machine in the canteen, had passed security checks, had a pass and had had their tools inspected. The other thing they needed like all visitors was an escort and the escort was supposed to stay with them throughout their visit. The canteen at 9:30am was empty apart from the technician and his escort who was sat in one of the high backed booths and could still see the work being carried out. A staff member walking past the canteen saw only the technician and raised the alarm. Security took less than two minutes to get there and find the escort watching everything as instructed. Panic over although the technician was a bit alarmed.

      New rule later that day was that if you were put on escort duty you must be visible at all times when escorting.

      1. Paul Hovnanian Silver badge

        Re: Interesting

        Anecdote: In my good old days working at Boeing, we had a challenge policy in place. See someone without a visible badge and ask.

        A bunch of us were going out to lunch just as an armed security guard was walking in. Being a typical Seattle rainy day, he was wearing a raincoat. With the badge underneath. As we all reached the front door at the same time, I stopped and asked, "Hey. Where's your badge?" He just grinned and opened his coat. My lunch companions were looking at me like I almost got everyone shot*.

        *Typical hoplophobes. I grew up around people open carrying. Particularly for a uniformed guard, it's almost expected.

        1. Anonymous Coward
          Anonymous Coward

          Re: Interesting

          I gave you an upvote, however hoplophobe almost lost you it

          Guards with guns are a lottery on response, TSA are worse - example I was coming through security after flying into LAX on my way to my next flight, lock on bag, tsa female officer is struggling with the lock, I say here let me get that and go to unlock it, quick as a flash she has a weapon drawn on me and is screaming step back from the bag NOW

          I recounted that to Canadian equivalent when they asked why I was asking if it was ok to unlock my bag for them, her reply "yeah the Americans are really highly strung," unnerved me more than the tsa did, as tsa.looked panicked, Canadian version looked very confident and assured, where it was more "if I draw my weapon it won't be for performative reasons"

          1. Claptrap314 Silver badge

            Re: Interesting

            You obviously have not had training in reaction times. And the article is about social engineering. Someone intending to trigger some sort of *interesting* response from whatever the bag is holding might do EXACTLY what you did. That TSA agent did the right thing.

            You do NOT make a move like that unless you enjoy Russian Roulette.

            1. Paul Hovnanian Silver badge

              Re: Interesting

              This, exactly.

              They are inspecting luggage for possible weapons. You can ASK to assist opening it. But reaching for it is what they would expect from someone about to be discovered carrying something nasty.

              1. Anonymous Coward
                Anonymous Coward

                Re: Interesting

                But this is the same TSA that confiscate suspected unstable homemade liquid explosive from you and throw it in a large clear plastic bin?

                In my day a misfired round meant a whole circus of EOD, fire service, range safety officer, etc etc. They must have developed really advanced clear plastic bins since then.

                1. Anonymous Coward
                  Anonymous Coward

                  Re: Interesting

                  The probability that there is even one container of liquid explosives in that bin of non compliant water bottles is vanishingly small. It's main function is deterrence. You are not boarding with a sufficient quantity of anything to be worth the trouble.

                  1. Yet Another Anonymous coward Silver badge

                    Re: Interesting

                    So there is no point in the whole pantomime other than "respect mah authority" ?

                    Also remember to salute the flag and say 3 hail marys or the communists will get you

              2. ChoHag Silver badge
                WTF?

                Re: Interesting

                Fuck everything about that and everything about your and the previous poster's mentality who have normalised this sort of abusive behaviour.

                It's a civilian airport not a warzone and it's my god damn bag.

                Hire people who aren't trigger-happy.

                1. Terry 6 Silver badge

                  Re: Interesting

                  Not too sure about that. Every airport is a potential war zone these days. Because a plane is a big tube full of humans hurtling through the air at speed. It's not as if history hasn't had its share of " incidents"

                  Come to that the terminal is probably quite an attractive target too. It most likely has plenty of whoever the terrorists don't like in there, lining up to wait to get on a plane..

                  1. Anonymous Coward
                    Anonymous Coward

                    Re: Interesting

                    You would have thought that the more intelligent terrorists would have thought of bombing the security queue

                    A couple of hundred people crowded together indoors before the security check.

                    And what would the response be, more security checks and slower lines and more crowds ?

      2. Richard 12 Silver badge
        Happy

        Re: Interesting

        Visible from where?

        Well done new hire, I hope they got a bonus for that!

      3. Excused Boots Silver badge

        Re: Interesting

        Just out of idle curiosity, what happened to the person who accosted the MD? I’d love to think that he or she was praised for doing their job, alas you never know.

        1. I ain't Spartacus Gold badge

          Re: Interesting

          There's a story from SAS history about this. In the 50s in pre-independence Malaysia, they were sent to help deal with an insurgency in the North (see Malaya Emergency). So they're getting in some much-needed jungle training somewhere "safe". A patrol goes out and comes back to the main camp using an improper approach procedure.

          Rather than just opening fire the guards sort it out by talking to them. For which the Colonel fines them. Jungle warfare is horribly close-range, so you have to have procedures to keep the enemy at a distance. In the SAS everyone gets fined for everything, and the money is used to pay for end-of-deployment piss-ups.

          Colonel then goes out and returns using incorrect procedure. Gets fired at by guards. Fines them for missing...

          1. CountCadaver Silver badge

            Re: Interesting

            Journalist was sent out in the last 20 years to visit a Gurkha training camp in the jungle, told where he is to go to, gets to the camp and queries the lack of guards with the officer and how lax it all seems

            Officer gives a signal and all up the path the journalist had walked down up pop various gurkha soldiers, many close enough to put a kukri through him...

            Iirc it made his blood run cold

            1. I ain't Spartacus Gold badge

              Re: Interesting

              There was a journalist in the late stages of the Falklands campaign who was going up towards the front with just an officer as minder. Officer needed a rest, so he was driving the jeep at night while the guy slept in the back. Suddenly he's surrounded by armed Gurkhas, who are asking questions about why a civilian is driving round the rear areas of their unit with military kit. His minder woke up and gave the password and all was well. But he described it as very scary, and he said the Gurkhas seemed genuinely disappointed that they couldn't finish him off.

              They were one of the SAS partner units in the Malaya Emergency. The SAS did deep jungle patrols to mess with the insurgents directly, and not allow them a safe haven to operate in. Meanwhile teams would go to the villages and kit them out with radios to call for help. They'd then do an exercise where the village would use this new radio, and 15 minutes later, helicopters full of Gurkhas would turn up to defend them.

        2. Anonymous Coward
          Anonymous Coward

          Re: Interesting

          MD had his ID on his belt but his jacket covered it. The MD apologised for covering it up and praised the individual for following the rules to the letter. New starter’s boss hastily did an all these people are directors course so there wasn’t a repeat.

      4. CountCadaver Silver badge

        Re: Interesting

        If i was the MD, I would have highlighted that a new start obeyed policy and confronted me, yet I was still getting reports of longer standing staff failing to confront unfamiliar faces

        When I was in college I worked in a petrol/gas station, now in Scotland, plod are NOT permitted to buy alcohol in uniform whether on or off duty, my brain logged age restricted product (as alcohol was the main category and tobacco was the other)

        Well one night in comes the chief superintendent for the area (for the USA folks think of 2 levels above who the dept captain answers to) in uniform, asks for whatever his favourite smokes were, my brain recalls no age restricted products to police officers in uniform.(And the penalties and legal headaches for breaching this), I politely refuse and cite why, he assures me that there is nothing stopping a police officer buying tobacco in uniform, I'm already aware of social engineering and I hold firm, sorry but to my knowledge I am legally NOT permitted to sell you tobacco while you are in uniform, he goes for the polite version of *I'm a police officer so I think I would know* (but wasn't aggro at all unlike many of his subordinates), he gives in and we part on friendly terms, I check later and realise my error and make a note to apologise if I see him again.

        Well he comes into see my boss, relays his tale, she being of the company mindset where laws got selectively enforced alongside the "do what coppers say if you want to avoid a kicking" worldview, apologises profusely and tells him she will give me what for and will haul me over the coals,

        he stops her right there and says "actually I came into praise him, it's good to see a young person who ISN'T intimidated by the uniform, he wasnt aggressive or rude, he was polite but firm, he stuck to what he knew and didn't back down, if that had been a test purchase then if he had given in then he and the company would have been in serious trouble. I'm pleased also to know that if he stood firm against a high ranking police officer it means he will hold firm against my subordinates and that's a good thing"

        My mum worked for the same company (started as a Saturday job and I kept it going while I was in college) so she was pleased (despite her being paranoid that if you talked to cops that either they would 'fit you up' for something or if someone saw you talking to a cop they would 'put your windaes in for being a grass'...no I have no idea why she thinks that way....)

      5. J.G.Harston Silver badge

        Re: Interesting

        I had a week working on one site where the escort was armed. :D

        1. Anonymous Coward
          Anonymous Coward

          Re: Interesting

          I've had that in the UK!

          Hence anonymous.

    3. DS999 Silver badge

      Re: Interesting

      Probably because they have outside vendors/sales consultants doing presentations with laptops they brought in, and it is too much of a pain to authorize that device for a half day's visit.

      1. MachDiamond Silver badge

        Re: Interesting

        "and it is too much of a pain to authorize that device for a half day's visit."

        Sure, let's exchange all of the security plan for a bit of convenience.

        It sounds like a great job for an IT PFY to get the consultant set up and torn down for the presentation. What's generally only needed is a way for them to connect their laptop to the projector/sound system, not a network. They can be told that they won't have internet access through the company's portal so it's not an option. If they need internet to demo something, it will have to be done in a conference room that has over-the-air cellular data so the consultant can "hot spot" their laptop.

        1. Anonymous Coward
          Anonymous Coward

          Re: Interesting

          Separated VLAN for guest access which is firewalled off from the rest of the company network?

          1. I could be a dog really Silver badge

            Re: Interesting

            That's what I was thinking - if you have a need for an "open access" port like that, make it generic internet access only. And if company users use it, their VPN kicks in.

    4. Terry 6 Silver badge

      Re: Interesting

      I'd assumed that there was an enforced password change every 3 months. Winterer2025, Spring2025....and so on year after year

    5. BartyFartsLast Silver badge

      Re: Interesting

      I guess because multiple devices from visiting employees, contractors and maybe even presenting vendors, clients etc etc need some sort of internet access but that's no excuse for such a lapse

    6. MrReynolds2U

      Re: Interesting

      If you're going to have a port without NAC it needs to be on a guest network that has no way of connecting to the protected/internal network.

      There's little point in having a self-service portal (with authentication) that allows you to add a device exception, as this will be abused for the sake of convenience.

  3. Evil Auditor Silver badge
    Facepalm

    "winter2023!"

    Darn! Why have I never thought of that. Forced password change every 90 days and I will never again forget a password.

    1. John Robson Silver badge

      Re: "winter2023!"

      I can't forget my password, because I don't know it...

      Generated by `openssl rand -base64 23` I can't be bothered to come up with repeated memorable passwords for something that requires me to change it repeatedly.

      Makes a mockery of MFA, but at least I'm unlikely to lose both of the things I have (one of which also requires either something I know or something I am to access)

      1. Yet Another Anonymous coward Silver badge

        Re: "winter2023!"

        If your forgotten password procedure is secure there is no need to know your password, if it's not secure then the best password in the world isn't going to help

        1. John Robson Silver badge

          Re: "winter2023!"

          Often it's quicker if you can enter the password, rather than going through the forgotten password dance.

      2. Anonymous Coward
        Anonymous Coward

        Re: "winter2023!"

        I can't forget my password, because I don't know it...

        Generated by `openssl rand -base64 23` I can't be bothered to come up with repeated memorable passwords for something that requires me to change it repeatedly.

        Makes a mockery of MFA, but at least I'm unlikely to lose both of the things I have (one of which also requires either something I know or something I am to access)

        how does that work when you need the password to log onto the computer?

        1. John Robson Silver badge

          Re: "winter2023!"

          Yubikey...

          I clearly edited that out of my original post, but it probably helps understand the "Makes a mockery of MFA" comment.

      3. Roland6 Silver badge

        Re: "winter2023!"

        My partner uses the typing without engaging brain password generator, if she’s on the iPad, she will most likely get the iPad to remember it, otherwise next time she visits the site it will be the “forgotten my password” routine which as you note can be construed to be a form of MFA…

  4. Headley_Grange Silver badge

    Years ago our company was going for List X status. IT went balls out before the initial audit - password policies, night-time checks of desk areas for post-its, senior management briefed that they were not "special", etc. Number one on the audit observations? Too many external doors into the building. If you think that C-suites get annoyed when you make them change their password every month you should see them when the door next to their parking space is permanently locked and they have to walk an extra 100 yards.

    1. ttlanhil

      If they don't like that, there are things many of them will dislike even more!

      In one of Deviant Ollam's stories of pentesting, one of the times he got rumbled after hours was because one of the workers saw his car on the weekend (driving past, not at work) and went to check it out.

      The workers all knew each other (so claiming to be from another site didn't work) and cared about the company - because they'd been there years/decades, because there was a good culture and management looked after staff

      1. Anonymous Coward
        Anonymous Coward

        Pity that didn't happen in Wyoming.

      2. MachDiamond Silver badge

        "because they'd been there years/decades, because there was a good culture and management looked after staff"

        How many companies look after their employees to the point where they'd have staff that have been there for years/decades? It's another reason why large turnover is an issue.

        1. This post has been deleted by its author

  5. ChrisMarshallNY
    Black Helicopters

    Old Advice

    The classic advice was to walk around, holding a clipboard.

    Likely, no longer applicable, but I suspect that a surreptitious photo of an employee access badge, and a color printer, could do wonders.

    1. Anonymous Coward Silver badge
      Thumb Up

      Re: Old Advice

      Don't forget the hi-vis vest. Nothing screams "authorised" as much as hi-vis.

      1. Evil Auditor Silver badge
        Thumb Up

        Re: Old Advice

        Hi-vis vest and a step ladder. And you don't even need to ask - they'll open and hold the doors for you.

        1. Anonymous Coward
          Anonymous Coward

          Re: Old Advice

          Don't forget "walking quickly" and "serious/concerned expression". Those will get a lot of doors opened for you too.

      2. C R Mudgeon Silver badge

        Re: Old Advice

        Indeed. I have a hi-vis rain jacket for cycling safety. At least once, while wearing it at an outdoor concert, I've been asked for help by another punter, despite a complete lack of official insignia.

    2. SamanthaFA

      Re: Old Advice

      mebbe update the clipboard for a tablet? ;)

      1. ttlanhil

        Re: Old Advice

        Depends where you are (type of industry) - in a lot of places, actual paper for the Official Paperwork is more believable for someone inspecting things

      2. Yet Another Anonymous coward Silver badge

        Re: Old Advice

        >mebbe update the clipboard for a tablet? ;)

        Another of Deviant's war stories. Have the permission + work order on a tablet, but then explain in your special "officious voice" that security isn't allowed to touch the tablet because it's a secured device under federal code THX1138 etc

      3. I ain't Spartacus Gold badge

        Re: Old Advice

        Replace the clipboard with some sandwiches. Nothing says "I belong here", like carrying your lunch back to your desk.

        1. Terry 6 Silver badge

          Re: Old Advice

          Yeah, trick there is to buy said sarnies from tthe place everyone goes to. Bonus if you can enter just behind a group retuning from their lunch buying.One suit with a Greggs bag looks just like another.

    3. Terry 6 Silver badge

      Re: Old Advice

      Oh yes. Had a temp job as a youth. Temp because it was shit, lousy pay and I'd already worked out that my predecessors got replaced about every three months.*

      So among the time wasting games I employed was wandering round with a clipboard- got me all round the building. No one ever questioned why I was there.

      *Job was filing away paper slips from people applying for a mail order catalogue. These had to be squeezed into plastic envelopes, so tightly that our fingers would bleed where they caught the plastic.

      But two minutes of looking at these files showed that the filing teams were replaced regularly.

      The slips would be perfectly ordered for a few weeks, then became less so, then were obviously just stuffed back in randomly. Then got orderly again, etc etc..

      Which as an aside, is an brilliant example of how crap the management were. There was no need to stuff the things in so tightly- the place had bags of empty room for filing cabinets. Given a less horrible filing system they could have had files in good order. Instead of something that made them fairly useless.(no one would have been able to locate the bloody** things)

      **Sometimes literally

    4. Withdrawn

      Re: Old Advice

      IME delivering flowers will open many doors.

      1. ChoHag Silver badge
        Trollface

        Re: Old Advice

        And not just doors...

    5. tl3

      Re: Old Advice

      I used to lecture in Cybersecurity in Higher Ed. Got to know a Red Team and the lead would do a guest lecture (sure, students would never skip HIS class, sigh). He said I would be amazing at such testing because who looks at a middle aged woman in a wheelchair as a challenge...*smug mode entered*

  6. s. pam
    Facepalm

    Some times the old ways are the best ways

    Sayeth the old grounds keeper in Skyfall...!

    Many a company has been pwned by piss poor perimeter security and this is a textbook example of how.

    1. Yet Another Anonymous coward Silver badge

      Re: Some times the old ways are the best ways

      There's an old New Yorker cartoon of an old man sweeping the street outside some US embassy.

      "Yes we know he's KGB" says one guard to the other "But he's doing such a good job"

  7. Apocalypso - a cheery end to the world Bronze badge
    Facepalm

    Challenge intruders

    Wait until AI security guard robots are roaming the hallways: you go to the loo and are challenged to show your ID and asked why you've had to leave your desk; you come back from the loo and are challenged to show your ID and asked why you've had to leave your desk. You go to the coffee machine and are challenged to show your ID and asked why you've had to leave your desk; you come back from the coffee machine and are challenged to show your ID and asked why you've had to leave your desk. You go to the printer in the room down the hall because the nearest one to you is out of toner and are challenged to show your ID and asked why you've had to leave your desk; you come back from the room down the hall with the working printer and are challenged to show your ID and asked why you've had to leave your desk.

    Only when it tries to sniff your breath and ask if you've been smoking in the loos do you realise that the robot is supposed to be patrolling the nearby high school but the kids have hijacked it!

    1. Anonymous Coward
      Anonymous Coward

      Re: Challenge intruders

      We don't have to wait. The police have been doing that for more than 20 years.

      I worked for a time as a driver for a large-format printing company. One of our high-volume clients was actually at the other end of the road from our print shop. One morning I had to make several deliveries to that client, and EVERY SINGLE TIME I got stopped driving BOTH DIRECTIONS through THE SAME CHECKPOINT not 5 minutes apart.

    2. This post has been deleted by its author

    3. Yet Another Anonymous coward Silver badge

      Re: Challenge intruders

      "Please put down your coffee. You have twenty seconds to comply."

      "You now have fifteen seconds to comply.

      1. This post has been deleted by its author

    4. Roland6 Silver badge

      Re: Challenge intruders

      As the kids will have hijacked it, you can expect to fail the challenges…

      Thats what a robot intruder would say

    5. Excused Boots Silver badge
      Terminator

      Re: Challenge intruders

      "you go to the loo and are challenged to show your ID and asked why you've had to leave your desk; ....”

      You have 20 seconds to comply!

    6. Anonymous Coward
      Anonymous Coward

      Re: Challenge intruders

      If they're anything like those Airport R2D2 droids you see carrying dirty dishes, they can easily be confused and sent in the wrong direction.

      Me and a mate of mine managed to get one to negotiate it's way around us into the open terminal area where it went on a grand voyage and never returned. Some say there have been sightings near the Toblerones, beyond the Duty Free fags.

      1. Yet Another Anonymous coward Silver badge

        Re: Challenge intruders

        Those actually are R2D2s. They booked a cheap ticket back to Tatooine on the intergalactic equivalent of Ryanair and somehow ended up having to change at Luton

    7. Anonymous Coward
      Anonymous Coward

      Re: Challenge intruders

      Then the administration challenges you to show your ID and ask why you destroyed the robot...

    8. David Hicklin Silver badge

      Re: Challenge intruders

      > you go to the loo

      And make sure you get a receipt !

  8. gosand

    I hope the Pi wasn't bare and was in a nice non-descript black case. A printed label stuck on it saying "DO NOT REMOVE - Test in progress" might have bought them another week or two.

    1. Yet Another Anonymous coward Silver badge

      Put it in an old thermostat case and it will be there until the building is torn down

  9. Inventor of the Marmite Laser Silver badge

    Just walk in like you own the joint.

  10. Boris the Cockroach Silver badge
    FAIL

    And this is

    why it was drilled into our little civil servant heads that if you were in a 'secure' area , you let no one in, and you let no one out. and you made sure that you knew who was on the list to be in that area.(usually 6-8 people)

    But the number of times home base got breached by shirt and tie wearers holding clipboards... sheesh. bloody MOD plod... more interested in searching our cars on the way out than stopping bad people getting in.

  11. ricardian1943

    At one government building the authorities would call an exercise "CHECKERS". This was a codeword broadcast on the internal Tannoy system and it meant that everybody including the (very) senior staff & any visiting Government ministers immediately had to challenge their neighbour(s) to show their official pass. Not infallible but it was better than nothing and meant the bosses were shown to be included

  12. Anonymous Coward
    Anonymous Coward

    Meanwhile the Blue Team...

    "But muh Splunk dashboard! Updates were installed! We have a CockMaster 9000 Turbo XL Firewall with extra girth and ribbed texture! They assured me it was 50x faster and could read log files 20ns faster!"

  13. Gavsky

    As mentioned in comments: clipboard, High Viz, stepladder, tool belt, 'manual working' clothes (as opposed to 'Manuel working' clothes - only successful in Spain/Portugal, or in countries with a glut of waiters).

    Helps if you have a lanyard which matches those worn by real visitors, pass ditto. Really helps if you know the name(s) of someone who works in 'facilities management', first name is fine. I bet you'd get into plenty of companies/Government departments etc.

  14. Anonymous Coward
    Anonymous Coward

    Unknown bloke wandering ariound, might be slightly questioned.

    Cracking blonde, gifted, great pins - says she's HR - never questioned - while all the men get Hot and Randy......

    1. Anonymous Coward
      Anonymous Coward

      Until someone remembers that no personnel department has hire any blond woman since the mid double zeros.

      1. Anonymous Coward
        Anonymous Coward

        I dunno man, personnel seems to the exclusive domain of waspy short blonde women.

  15. Throatwarbler Mangrove Silver badge
    Coat

    Shoveling

    In my time in IT, I certainly did plenty of shoveling. It weren't snow, however.

  16. njorl

    The final twist is that the head of the maintenance department set the whole thing up to bum some free labour out of the CIO's budget. Nerds are only smart in their own, nerdy, way.

    1. Yet Another Anonymous coward Silver badge

      We rely on red team pen-testers for all our IT needs.

      If you have the right attitude to your users it's very cost effective

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon