Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is security best practices 101 stuff. :) See the swiss cheese model, which applies here:

https://en.wikipedia.org/wiki/Swiss_cheese_model

It’s not smart to rely on a single point of failure to protect everything 100%. Maybe if you’re protecting home movies lol. But at the Louvre? Sheesh…

- What if the routers / modems have a security vulnerability?

- What if there’s (accidentally) an exposed ethernet cable somewhere in the museum that would let someone immediately access a private VLAN?

- What if someone breaks into the security room? either physically breaking the door down or stealing the keys to the room. That’s one of the first few passwords i’d guess as a thief.



Nobody said anything about a single point of failure. Just that we need more context to figure out how important this is. Kind of like the zeros for the US nuclear weapons https://www.zmescience.com/other/offbeat-other/us-nuclear-la...

> What if someone breaks into the security room?

Normally a security / monitoring room has the cameras on the screen 24/7, so once you somehow get in and somehow there's nobody there and somehow nobody notices you breaking in... you just look at the screen.


I agree it is hard to assess the impact just for that article alone.

Regarding the security room - sure the feed is live on the screen. That makes sense. But I would definitely expect more “admin” related features to require a login though. Like deleting footage, disabling a specific camera, etc.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: