logoalt Hacker News

jurgenburgentoday at 7:15 AM1 replyview on HN

Of course. Doesn’t mean we should leave the root password written down on a post-it next to the hardware. It sounds strange that such a privileged port has no authentication.


Replies

Ekarostoday at 9:35 AM

Getting security to work reliably in such scenarios can be hard. And your customer really don't want their up to hundred million in cost pieces of equipment sit there doing nothing because maintenance is unable to do something with it.

Much simpler just to instruct to physically secure the conduit around... Even better if that is already approved and demanded process.