Skip to content

Comment on A team paid to break into top-secret basesparent

Comments

This what security people refer to as "tailgating" and at one office, our security people were trained to spot this. I tried several times when I had lost my ID and got yelled at and had to get a visitor pass for the day.

Another very large tech company the security people DGAF about anything. You could forget your ID, tailgate someone, no problem. I started doing this to see how often I could do it, even when I had my ID. Security never stopped me, but when one of the C-suite folks did a badge scan, my manager got an earful wondering why I was never in the office. Which then resulted in a lengthy meeting with my manger, his director and another director. Imagine their surprise when they found out I was pseudo pen testing their security systems and pointed out that the security firm the company had hired was doing a horrible job. They obviously were not impressed and told me to stop doing it.

I also read a recent version where a team were doing this on purpose to get a person's ID scanned with some kind of a NFC scanner. Of course they would get kicked out for not having an ID or an appointment, but it didn't matter. They already had gotted several different employee ID's they could duplicate and use. They even managed to get some guy pretty high up who had an encrypted RFID ID card and managed to crack the encryption which allowed them to get into all kinds of restricted areas.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.