7 ms·
When I clicked on the link, I expected to see an unlocked closet primarily used to store mops, floor wax and boxes of copier paper. Instead, I saw a small carp
by gregholmberg 14y ago
When I clicked on the link, I expected to see an unlocked closet primarily used to store mops, floor wax and boxes of copier paper.
Instead, I saw a small carpeted room containing a half-full rack of telecom gear, featuring several Ethernet switches providing 100 or so switchports for end users, punchdown blocks for terminating phone service to a similar number of incoming lines, and a small number of switchports on what looks like an administratively privileged network via a second smaller switch.
The list price of the larger Cisco with all three power supplies and several 24-port GigE cards was at least $15,000 the last time I had to buy one.
The fiber uplinks to other rooms (provisioned like this one, or better, typically one per wing on each floor of a large building) are likely to carry some very interesting traffic -- not just between end users and their preferred servers, but between the large switches themselves, possibly even routing outbound traffic for the "administrative" switch, as well.
I sometimes use separate "control plane" switched media to access "remote power strips". These allow an admin to remain seated at a desk while rebooting machines all over the campus.
Allowing unrestricted access to a storage closet containing that much gear (uninstalled) is irresponsible. Theft is likely.
Allowing unrestricted access to a wiring closet containing that much gear (provisioned, configured, and running in production mode) is a hilarious wtf. The imagination soars ...
Allowing unrestricted physical access to any administrative switch that carries traffic for power-cycling campus equipment on and off remotely is a fairly serious oversight, and not in the least bit hilarious.
edit: It looks like the photos show two different rooms. The wiring closet itself has a bare concrete floor.
- jasonzemos 14y agoI'm not surprised. That seems to be the MIT ethos since Stallman proclaimed the best account password for all users was the enter key.
- sp332 14y agoIt wasn't just Stallman. Hacker subculture has always contained an element that is opposed to unequal access, like locks. And it's still going strong; last month's CCC hacker conference in Hamburg had a large lockpicking workshop. http://events.ccc.de/congress/2012/wiki/Lockpicking_Area http://events.ccc.de/congress/2012/wiki/Lockpicking_Area
- meaty 14y agoHe forgot the human condition when he came up with that...
- carlob 14y agoSeveral times while visiting Boston, I have entered the medialab on weekends and no one prevented me from getting a good tour of the building. I always thought this was part of the MIT culture, not a blunder of security.
- Timmmmbob 14y agoThat's how all universities work. It's quite impractical to secure them properly, and nobody can hope to recognise all the students (and visitors!) so you can basically walk around any university and as long as you look like you belong there nobody will challenge you.
- carlob 14y agoNo, I'll have to disagree here. I've spent around 10 years in several universities both in Europe and the US and most of them are closed during weekends and you can't walk around and touch experiments when no one is around. MIT is special in its openness, or at least the Medialab is (you can't really walk in any lab of the Physics department).
- tjr 14y agoYet they lock the doors to the classrooms, in which are chalkboards and chairs...
- deleted 14y ago[deleted]
- dlitz 14y agoDeliberate openness is irresponsible now?
- gregholmberg 14y agoI remember being invited to visit the cockpit of a commercial airliner during a flight when I was little. On US airlines, at least, that kind of openness is a distant memory. If you don't work in network security, you might find it unsettling to see just how much additional trouble a person can cause by having physical access to the hardware itself -- the cables and ports and LCD front panels and the like. As an example, here's a dirty secret: in quite a few of the large, institutional settings I have had access to, the hash of the IOS enable password is stored on local flash inside the machine, and set to the same string across many core devices. This means that if you can compromise one switch (perhaps a small one in a basement closet), you could also have privileged access to larger switches deep inside data centers on the same campus. Compromising the first switch is much easier if you can attach a serial console and reboot it at will. If I were serious about doing something like this, I might even bring an extra switch along to substitute in, so the regular users of the network would see no downtime. Groups of switches inside a data center (when viewed with eyeballs) have a kind of tedious homogeneity to them. Generic faceplates all in rows, kudzu of brightly-colored generic cables fanning out in every direction, armies of green LEDs flashing with traffic, thick black ropes of power cables in back ready to wiggle loose from a stray nudge. Aloof. Opaque. The traffic to and from each data center switchport, though, is often highly individual. Many times it is deadly dull for port after port after port. But sometimes, you see that you are watching a machine that appears to be processing payroll. Or saving a series of very expensive and proprietary chip masks to some huge file server. Or, best of all, you might see millions of rows of data describing those things and more, all being stored as tidy SQL. So yes, I draw the line somewhere short of allowing homeless people into a space where they would be sleeping next to network devices with important roles.
- jrockway 14y agoWhat's the point of link-level security when governments control the CAs and global routing tables anyway? You're probably being spied on right now, and not because someone has physical access to a mop closet with some switches in it.