Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Depends. Some have a paranoid mode without caching, because then a physical attacker cannot snip a cable and then use a stolen keycard as easily or something. We had an audit force us to disable caching, which promptly went south at a power outage 2 months later where the electricians couldn't get into the switch room anymore. The door was easy to overcome, however, just a little fiddling with a credit card, no heroic hydraulic press story ;)


Auditors made you disable credential caching but missed the door that could be shimmed open..


Sounds like they earned their fee!


If you aren't going to cache locally than you need redundant access to the server like LTE access and plan for needing to unlock the doors if you lose access to the server.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: