Hacker News new | ask | show | jobs
by drblast 2743 days ago
Not surprising at all. What's surprising is that it's taken this long to appear in the news.

While in the shipyards for maintenance I would stand watch and was responsible for letting people on/off a large ship. Most were contractors. The only requirement was that they had a contractor badge. How did we tell this was a valid badge? Good question. You'd think there would be some sort of master list of people with badges we could check and verify.

Not quite. Every contractor had their own style of badge and we had no way of knowing if any particular badge was real or not. Want a "valid" badge? Buy a badge printer. You're in.

We had people we didn't even know just show up to install systems on board that nobody was able to verify were supposed to be there or not. It was a little better with the classified systems, but you can imagine that any verification of contractor IT systems was non-existent.

1 comments

I can't believe it, but I also can believe it - Me, ever since doing CyberSec 2 years ago.