Hacker News new | ask | show | jobs
by wolvoleo 3 days ago
Exactly. At work I now have to MFA and type a random code every time I want to book a desk. It kills the session after 30 minutes. It's ridiculous. If an attacker ever got hold of it, they could... book a desk at that shitty office for me. Whoopty doo what horror.

The same with logging my hours in a different system. I only use those systems for those things, nothing else.

Security is important for things that actually hold value. Like when I connect to my admin account. Or even when I connect to our intranet. But they enforce the highest level even for stupid stuff.

1 comments

One insider threat actor might book a previously unbugged desk, bug it with multi-antenna keystroke logger (making and breaking resistive connections across parasitic capacitance nodes, changes the direction dependent EM scattering function). One can correlate acoustic key press detection with changes in scattering, unsupervised.

Fixed desks are way more secure than promiscuous desk multiplexing.

An insider threat actor can just do that without booking the desk. They just go in on a quiet day and sit down, nobody checks whether a desk is booked unless they themselves need to sit there.