4 ms·
Is there a ‘server room’ in the Capitol? Was is breached?
by themark 6y ago
Is there a ‘server room’ in the Capitol? Was is breached?
- deleted 6y ago[deleted]
- ilikepi 6y agoThere probably is, and it probably wasn't. There's a big difference between an office of someone who regularly meets with visitors and a room that is likely limited to a handful of people under controlled circumstances. It's likely there's a whole secured area of the building dedicated to operations (telecomm, engineering, etc).
- gibolt 6y agoThey did enter several congresspeople's offices, with at least Pelosi's computer completely unlocked. Emergency situation meant they left immediately, and potentially left the whole government vulnerable to future attacks in the process
- ilikepi 6y agoOh totally... It's slightly surprising there's not an emergency evacuation procedure for people who work in the building that involves locking all devices that remain in the building via a hot-key or hot-corner. Come to think of it, I wonder if a screen lock command is something that could be pushed from a Windows domain controller...and if so, why wasn't that used?
- banana_giraffe 6y agoWindows 10 can be setup to auto-lock if a bluetooth phone goes out of range, and there's a little eco system of third party companies that make keyfobs that do the same basic thing. Even if it's not a common feature, it's not like I'd be surprised to learn these computers are imaged with some custom software, one of which could be a lock on command (or loss of connectivity to home). I have no idea how important these machines were, of course.
- astrange 6y agoA government computer should be set to lock as soon as the CAC is removed, and staffers shouldn’t be leaving their CAC in the machine even if they’re fleeing, or else they’ll be locked out of the building. So something obviously went wrong there.
- marvion 6y agoI've seen "just WIN+L" on Twitter a lot... Relying on humans locking their PC in event of a terrorist attack isn't a IT-Security concept. Security consists of a threat model and many layers of security measures. Many many outer layers have failed here. I wouldn't blame an individual nor a department here. It's one of those events that probably wasn't in the scope. Additionally, roles/security clearance levels etc. still work regardless of the account beeing open to anyone. Things like Smartcards, Yubikeys, auto-lockscreen could have failed the same way. Maybe a GPO failed, or a windows update broke the auto-lock.... that's why all these many layers exist.
- 8note 6y agoIt's kinda ridiculous that protest turns to riot and they break in wouldn't be in scope for a place with constant protests outside
- EE84M3i 6y ago>at least Pelosi's computer completely unlocked. The report I saw before was one of her staffer's computers was unlocked. Was there a report about her personal computer? (Does she even use one..?)
- wtallis 6y agoThe photos I saw of an unlocked computer were clearly an entirely different desk than the one shown in the photos that have been identified as being Pelosi's own office. It appears the unlocked computer was most likely for one of her staffers in a different room that may have been part of the Speaker's suite.
- lostlogin 6y agoArs has a bit on that. https://arstechnica.com/tech-policy/2021/01/pro-trump-reporter-gloats-over-access-to-fleeing-hill-staffers-computer/ https://arstechnica.com/tech-policy/2021/01/pro-trump-report...
- paxys 6y agoWhile there may still be one, government data is now rapidly moving to private instances of AWS/Azure. And with standard encryption and backups even getting hands on sensitive hardware won’t be as catastrophic as loose sheets of paper on desks and by printers.