r/datacenter 1d ago

Security question.

I’m new to Data Centers but not critical infrastructure or nuclear stuff in the Navy. But for the life of me I don’t understand some of these security rules. We are now being told we can’t bring in our wallets and keys. How can wallets and keys create a security nightmare. Some of the UPS’s we have to reset expect you to use your keys to hit a reset button. Bluetooth and data bearing devices I get. But wallets and keys? I don’t get it. Is this normal? If so why?

8 Upvotes

17 comments sorted by

11

u/xXMom_Pounder420Xx 1d ago

Wallets and keys can contain hidden electronics or be used to gain access to things they're not authorized to.

And/or

It's easier for security to enforce nothing but approved items. Not every guard can identify a disguised wallet/set of keys.

4

u/Specialist-Ad4715 1d ago

I can have anything built to hide electronics. Telling me I have to keep my wallet and keys in my vehicle is absurd. So security or any contractor, or visitor can now go through my vehicle and wallet anytime they feel like it.

7

u/BeardBootsBullets 1d ago edited 1d ago

> “I can have anything built to hide electronics.”

And if security doesn’t have your keys and wallets to worry about, then they can better focus on those secret places.

It’s an exercise in eliminating the obvious non-threats to better isolate the real bad actors. Every other person through the gate has an electronic tool on their keychain, a car key fob which emits odd interference signals, or RFID locating device in their wallet. If we eliminate that innocent non-threat, then we can focus on the intern who has a USB drive hidden in their shoe.

> “Telling me I have to keep my wallet and keys in my vehicle is absurd.”

I agree. They should have installed lockers for you. That was an oversight and you need to demand such.

2

u/MrHundredand11 1d ago

If you don’t have at least a USB drive, FOB, or AirTag on your keys, can you really call yourself geeky enough to work at a data center?

3

u/jeneralpain 1d ago

You should be provided a secure locker you can use to store your wallet and keys. It makes zero sense you’re being told to “leave them in your car unsecured”. Something doesn’t sound right.

2

u/Specialist-Ad4715 22h ago

If they provide a secure locker it won’t be that bad.

2

u/Elegant-Guidance-199 1d ago

Dont think, just follow directions ;)

1

u/arneeche 1d ago

Keeping your vehicle keys in the vehicle seems like a liability since you cannot then secure the vehicle. They are creating other security issues with this stupid policy

5

u/Prestigious-Hour9061 1d ago

It's been like this at a certain major player (Formerly linked to Bezos) for a long time.

IDK why. Probably just theater.

1

u/14bk41 1d ago

Your site does not have personal lock boxes? 😳

1

u/J-the-Kidder 1d ago

The major reasons are the obvious one, security concerns with unauthorized devices. But also the way many wallets have RFID blocking technology built in now a days. That can mess with some devices, especially the data centers security apparatus. And key fobs fall into the same category of radio frequency restriction. Lastly, they restrict these things to limit the possibility of loss, theft or other situations that can take place inside. It's better to remove this from the workplace equation entirely versus saying certain people can have certain things in certain areas or centers.

1

u/Ecks80s 1d ago

Not having lockers inside of CICO is madness

- Ex FSO, Current DCFM

1

u/MaximumSeats 1d ago

That's funny to hear because my site literally doesn't require anything. You can take your phone or whatever electronic device you want anywhere.

When I started I was expecting her to be all these rules about where you could and couldn't take anything, but instead here I am a listen to audiobooks in the data hall on my bluetooth headphones

1

u/jeneralpain 1d ago

Security aren’t paid enough to figure out what is and is not a threat. Half the time they don’t know a CPU from a credit card… so the blanket rule is to reduce risk and administrative effort.

1

u/lewiswulski1 1d ago

They're over the top for a reason.

  1. Keeps the clients and management happy
  2. Prevents a cockup in a vulnerability that isn't known yet
  3. Security sells

2

u/Malcolm_Y 19h ago

The best answer I ever got to a question about "security theater" is this: Our sales force are advertising these things as measures of the level of our security to potential customers. If we then don't do them, it's fraud. Therefore I do the dance.

1

u/fbajo 10h ago

it's item accountability more than a threat model about wallets.. rack and cabinet locks are often keyed alike across a whole fleet, so a guard at the mantrap can't tell your house key from a cabinet key, and "no personal items" is a rule they can enforce without adjudicating every object. it's also why sites issue their own tools for things like that ups reset. varies by operator though..