Lets kill some IT dudes…….

Posted on September 5th, 2008 by Drazen Drazic

This article in CW reminded me of a story in Hong Kong many years ago during an audit we did.

Looking at the Data Center controls for a large multinational….in the event of a fire/emergency/disaster, the Data Center doors would lock immediately……Anyone in there, would not be able to get out! Seriously!

We had to explain to the CEO that more than likely, IT staff were going to be in there at any point in time. Once the gas (very toxic) started, you would be killing your staff.

Response: “Oh…You think we should change that?”

Well in Australia we would have…….I hope…….

Haven’t been back since….I hope it has changed. Really I do!

2 Responses to “Lets kill some IT dudes…….”

  1. Methinks as with the problem of data breaches (sharing of incident/log/flow data), we would not share half of the stories whereupon the comms/systems ground to a halt :) I will however give you one example whereby I, ‘erm, got a netmask incorrect during internal vul scanning and DOS’d the internets/extranet connections in an org via default route to fw’s as a catch all. /8 with many threads hitting many subnets… killed my own scanner C&C also, nooooooooooooooo! I think DD might be across this one :)

    Aside: In 3rd world countries, data centers experience rolling brownouts, their DR/redundancy/power is tested sometimes up to 10+ times a day.

    In Japan one telco built their data center underground yet still above a nuclear power plant whereupon they would flip the circuits/backup power in real time during tours of the facility! Nice.

    I’m a little bit troubled by certain encumbent Telco’s power infrastructure/redundancy/BCP and how untested, weak and tightly coupled + over-extended it is. Starting to actually think AU needs “blackops” to poke/probe demonstrate not just CTF/war games! Would we be safer in the long run? Kinda like the issue of scoping pen tests… To DOS and/or demonstrate pwnage, or just pretend…. sometimes the lights need to go off and unfortunately the needs of the many may outweigh the needs of the few to make a point! Am well aware of legality/process/practice/humanity issues here, however I think I may need to revive/re-purpose http://www.ipwarfare.com/ :) Muhuhuhahahahahahah!

  2. Declan Ingram Says:

    This does happen in Australia. Infact, I have worked in a Data Centre which had this. It sounds harsh, but there can be good reason for it.

    It’s not just the people stuck in there, though, imagine being a guard having to watch everyone inside trying to get out on the CCTV :(

Leave a Reply